2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-53808HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms ne...
CVE-2024-53804HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Emb...
CVE-2024-53803HIGH8.8Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access...
CVE-2024-21571HIGH8.1Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables...
CVE-2024-10516HIGH8.1The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and inc...
CVE-2024-10776HIGH8.2Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an att...
CVE-2024-10774HIGH7.3Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web...
CVE-2024-10772HIGH8.8Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high imp...
CVE-2024-10771HIGH8.8Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code...
CVE-2024-53907HIGH7.5An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method an...
CVE-2024-53142HIGH7.8In the Linux kernel, the following vulnerability has been resolved: initramfs: avoid filename buffer overrun The initr...
CVE-2024-53141HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap...
CVE-2024-11728HIGH7.5The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'vis...
CVE-2024-11460HIGH7.5The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions...
CVE-2024-11289HIGH8.1The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via se...
CVE-2024-11323HIGH8.8The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privil...
CVE-2024-11178HIGH8.1The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. ...
CVE-2024-11585HIGH7.5The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing ...
CVE-2024-10578HIGH8.8The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability ...
CVE-2024-52798HIGH7.7path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular exp...
CVE-2024-38910HIGH7.5Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in th...
CVE-2024-37862HIGH7.3Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-hum...
CVE-2024-37860HIGH7.3Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allo...
CVE-2024-30964HIGH7.8Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig...
CVE-2024-30963HIGH7.8Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now