2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13155MEDIUM5.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-13445MEDIUM5.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-49782HIGH8.2IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS...
CVE-2024-49780MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system....
CVE-2024-49355MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enab...
CVE-2024-43196MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0  application could allow an authenticated user to manipulate data in the Question...
CVE-2024-6697MEDIUM6.5The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functional...
CVE-2024-6696MEDIUM4.9The product implements access controls via a policy or other feature with the intention to disable or restrict accesses ...
CVE-2024-37363MEDIUM6.5The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (C...
CVE-2024-37362MEDIUM6.3The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauth...
CVE-2024-37361CRITICAL9.9The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-5...
CVE-2024-12284HIGH8.8Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
CVE-2024-5706HIGH8.8The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input befor...
CVE-2024-5705HIGH8.8The product performs an authorization check when an actor attempts to access a resource or perform an action, but it doe...
CVE-2024-37360MEDIUM4.4Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-...
CVE-2024-37359HIGH8.6The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but ...
CVE-2024-10339Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-53974MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-45777MEDIUM6.7A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_ge...
CVE-2024-52541HIGH8.2Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access cou...
CVE-2024-45084HIGH8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to con...
CVE-2024-45081MEDIUM6.5IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modif...
CVE-2024-28780MEDIUM5.9IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client  uses weaker than expected cr...
CVE-2024-28777HIGH8.8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserializat...
CVE-2024-28776MEDIUM5.4IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now