2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54756CRITICAL9.8A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe...
CVE-2024-7141MEDIUM5.9Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.
CVE-2024-55457MEDIUM6.5MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit th...
CVE-2024-54961MEDIUM6.5Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple ...
CVE-2024-54960MEDIUM6.5A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted pa...
CVE-2024-54959MEDIUM6.1Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabli...
CVE-2024-54958MEDIUM6.1Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw al...
CVE-2024-46933HIGH7.7An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH ...
CVE-2024-57716HIGH7.5An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselecta...
CVE-2024-57401CRITICAL9.8SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code...
CVE-2024-49781HIGH7.1IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when ...
CVE-2024-49779HIGH8.8IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, cau...
CVE-2024-49344MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application estab...
CVE-2024-49337MEDIUM5.4IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation...
CVE-2024-6432MEDIUM5.4The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘conte...
CVE-2024-13855MEDIUM4.3The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2024-13849MEDIUM4.8The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2024-13802MEDIUM5.4The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_e...
CVE-2024-13792CRITICAL9.8The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode executi...
CVE-2024-13789CRITICAL9.8The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de...
CVE-2024-13753HIGH8.8The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2024-13748MEDIUM4.8The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title paramet...
CVE-2024-13520MEDIUM5.3The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-13476HIGH7.5The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_...
CVE-2024-13888MEDIUM6.1The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now