2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13494MEDIUM4.3The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-10545LOW3.5The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image...
CVE-2024-57685MEDIUM5.3An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.
CVE-2024-56525CRITICAL9.8In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journ...
CVE-2024-53544CRITICAL9.8NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability...
CVE-2024-53543MEDIUM5.4NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability...
CVE-2024-53542MEDIUM6.5Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Tim...
CVE-2024-57608MEDIUM6.5An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.
CVE-2024-57026MEDIUM6.1TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that al...
CVE-2024-54820CRITICAL9.8XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login ...
CVE-2024-56897CRITICAL9.8Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API ...
CVE-2024-12918HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Hea...
CVE-2024-12917HIGH8.3Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorre...
CVE-2024-12916HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Lif...
CVE-2024-5174MEDIUM5.3A flaw in Gliffy results in broken authentication through the reset functionality of the application.
CVE-2024-13822MEDIUM6.1The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter...
CVE-2024-13605MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ...
CVE-2024-12308MEDIUM5.4The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outp...
CVE-2024-55898HIGH8.5IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated pri...
CVE-2024-13728MEDIUM6.1The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the r...
CVE-2024-52939HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2024-47896LOW3.3Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2024-46975HIGH7.9Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data in...
CVE-2024-12577HIGH7.3Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2024-13869HIGH7.2The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now