2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12917HIGH8.3Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorre...
CVE-2024-12916HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Lif...
CVE-2024-5174MEDIUM5.3A flaw in Gliffy results in broken authentication through the reset functionality of the application.
CVE-2024-13822MEDIUM6.1The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter...
CVE-2024-13605MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ...
CVE-2024-12308MEDIUM5.4The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outp...
CVE-2024-55898HIGH8.5IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated pri...
CVE-2024-13728MEDIUM6.1The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the r...
CVE-2024-52939HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2024-47896LOW3.3Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2024-46975HIGH7.9Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data in...
CVE-2024-12577HIGH7.3Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2024-13869HIGH7.2The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads...
CVE-2024-13564MEDIUM5.4The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-13798MEDIUM5.3The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in al...
CVE-2024-13474HIGH7.5The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id...
CVE-2024-12467MEDIUM6.1The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters'...
CVE-2024-12038MEDIUM5.4The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-13899HIGH7.2The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 ...
CVE-2024-13873MEDIUM4.3The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-22341HIGH7.5IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7....
CVE-2024-45674LOW3.3IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro...
CVE-2024-57176HIGH7.6An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal an...
CVE-2024-55159MEDIUM4.2GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/l...
CVE-2024-55156MEDIUM5.5An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows att...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now