2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13314LOW3.5The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its set...
CVE-2024-11260HIGH7.5The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injecti...
CVE-2024-13883MEDIUM4.3The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-13818HIGH7.5The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C...
CVE-2024-13751MEDIUM5.4The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all ...
CVE-2024-13672MEDIUM5.4The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-13537MEDIUM5.3The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. Th...
CVE-2024-13388MEDIUM5.4The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' s...
CVE-2024-13379MEDIUM5.4The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2024-13235MEDIUM6.5The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'l...
CVE-2024-38657MEDIUM4.9External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version...
CVE-2024-7131——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-54756CRITICAL9.8A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe...
CVE-2024-7141MEDIUM5.9Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.
CVE-2024-55457MEDIUM6.5MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit th...
CVE-2024-54961MEDIUM6.5Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple ...
CVE-2024-54960MEDIUM6.5A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted pa...
CVE-2024-54959MEDIUM6.1Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabli...
CVE-2024-54958MEDIUM6.1Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw al...
CVE-2024-46933HIGH7.7An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH ...
CVE-2024-57716HIGH7.5An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselecta...
CVE-2024-57401CRITICAL9.8SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code...
CVE-2024-49781HIGH7.1IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when ...
CVE-2024-49779HIGH8.8IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, cau...
CVE-2024-49344MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application estab...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now