2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31629Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-31628Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-31627Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-31626Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-31625Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-31624Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-31623Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-31622Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-20405MEDIUM6.1A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t...
CVE-2024-20404MEDIUM5.3A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t...
CVE-2024-24790CRITICAL9.8The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning f...
CVE-2024-24789MEDIUM5.5The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implement...
CVE-2024-5629HIGH8.1An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided...
CVE-2024-4812MEDIUM4.8A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Desc...
CVE-2024-3716MEDIUM6.2A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue le...
CVE-2024-36837HIGH7.5SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProduct...
CVE-2024-35673MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Pure Chat by Ruby Pure Chat.This issue affects Pure Chat: from n/a th...
CVE-2024-5459MEDIUM4.3The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missi...
CVE-2024-3469MEDIUM6.1The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all ver...
CVE-2024-5526CRITICAL9.1Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simple...
CVE-2024-1662HIGH7.5Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint S...
CVE-2024-4001MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_logi...
CVE-2024-5536MEDIUM5.4The GamiPress – Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gamipress_link s...
CVE-2024-5571MEDIUM5.4The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute...
CVE-2024-4821MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now