2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45418HIGH8.8Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to ...
CVE-2024-45417MEDIUM5.5Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privile...
CVE-2024-36259MEDIUM6.5Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attac...
CVE-2024-12368HIGH8.8Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user...
CVE-2024-11955MEDIUM6.1A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is ...
CVE-2024-54444MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento...
CVE-2024-34036MEDIUM4.3An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the...
CVE-2024-34035MEDIUM5.7An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must fl...
CVE-2024-34034MEDIUM5.7An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, trigg...
CVE-2024-12424Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-24592. Reason: This candidate is a ...
CVE-2024-51539LOW2.3The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulner...
CVE-2024-13695MEDIUM5.4The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 ...
CVE-2024-13693MEDIUM5.3The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-ex...
CVE-2024-13494MEDIUM4.3The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-10545LOW3.5The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image...
CVE-2024-57685MEDIUM5.3An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.
CVE-2024-56525CRITICAL9.8In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journ...
CVE-2024-53544CRITICAL9.8NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability...
CVE-2024-53543MEDIUM5.4NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability...
CVE-2024-53542MEDIUM6.5Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Tim...
CVE-2024-57608MEDIUM6.5An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.
CVE-2024-57026MEDIUM6.1TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that al...
CVE-2024-54820CRITICAL9.8XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login ...
CVE-2024-56897CRITICAL9.8Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API ...
CVE-2024-12918HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Hea...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now