2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53808 | HIGH | 7.2 | 0.6% | Dec 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms ne... |
| CVE-2024-53804 | HIGH | 7.5 | 0.6% | Dec 6, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Emb... |
| CVE-2024-53803 | HIGH | 8.8 | 0.5% | Dec 6, 2024 | Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access... |
| CVE-2024-21571 | HIGH | 8.1 | 0.2% | Dec 6, 2024 | Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables... |
| CVE-2024-10516 | HIGH | 8.1 | 6.5% | Dec 6, 2024 | The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and inc... |
| CVE-2024-10776 | HIGH | 8.2 | 0.5% | Dec 6, 2024 | Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an att... |
| CVE-2024-10774 | HIGH | 7.3 | 0.4% | Dec 6, 2024 | Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web... |
| CVE-2024-10772 | HIGH | 8.8 | 0.3% | Dec 6, 2024 | Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high imp... |
| CVE-2024-10771 | HIGH | 8.8 | 1.1% | Dec 6, 2024 | Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code... |
| CVE-2024-53907 | HIGH | 7.5 | 1.4% | Dec 6, 2024 | An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method an... |
| CVE-2024-53142 | HIGH | 7.8 | 0.2% | Dec 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: initramfs: avoid filename buffer overrun The initr... |
| CVE-2024-53141 | HIGH | 7.8 | 0.4% | Dec 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap... |
| CVE-2024-11728 | HIGH | 7.5 | 13.3% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'vis... |
| CVE-2024-11460 | HIGH | 7.5 | 0.5% | Dec 6, 2024 | The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions... |
| CVE-2024-11289 | HIGH | 8.1 | 0.7% | Dec 6, 2024 | The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via se... |
| CVE-2024-11323 | HIGH | 8.8 | 0.4% | Dec 6, 2024 | The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privil... |
| CVE-2024-11178 | HIGH | 8.1 | 0.6% | Dec 6, 2024 | The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. ... |
| CVE-2024-11585 | HIGH | 7.5 | 0.6% | Dec 6, 2024 | The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing ... |
| CVE-2024-10578 | HIGH | 8.8 | 1.3% | Dec 6, 2024 | The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability ... |
| CVE-2024-52798 | HIGH | 7.7 | 0.8% | Dec 5, 2024 | path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular exp... |
| CVE-2024-38910 | HIGH | 7.5 | 0.5% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in th... |
| CVE-2024-37862 | HIGH | 7.3 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-hum... |
| CVE-2024-37860 | HIGH | 7.3 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allo... |
| CVE-2024-30964 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig... |
| CVE-2024-30963 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now