2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27109HIGH7.6Insufficiently protected credentials in GE HealthCare EchoPAC products
CVE-2024-27108MEDIUM6.8Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
CVE-2024-27107CRITICAL9.6Weak account password in GE HealthCare EchoPAC products
CVE-2024-27106MEDIUM5.7Vulnerable data in transit in GE HealthCare EchoPAC products
CVE-2024-26238HIGH7.8Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
CVE-2024-26007HIGH7.5An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows...
CVE-2024-23105HIGH7.5A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2...
CVE-2024-1630HIGH7.7Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound de...
CVE-2024-1629MEDIUM6.2Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device comp...
CVE-2024-4871MEDIUM6.8A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being c...
CVE-2024-4860MEDIUM6.1The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerab...
CVE-2024-4859MEDIUM5.7Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL.
CVE-2024-4810Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE has been replaced b...
CVE-2024-4761HIGH8.8Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds...
CVE-2024-4624MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPres...
CVE-2024-4473MEDIUM5.4The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget...
CVE-2024-4445MEDIUM4.3The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-4440MEDIUM6.4The 140+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-4392MEDIUM5.4The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2024-4333MEDIUM5.4The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem...
CVE-2024-4144MEDIUM6.5The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all v...
CVE-2024-4139MEDIUM4.3Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resu...
CVE-2024-4138MEDIUM4.3Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resu...
CVE-2024-3579MEDIUM6.1Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker m...
CVE-2024-3374MEDIUM5.3An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to atte...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now