2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5705HIGH8.8The product performs an authorization check when an actor attempts to access a resource or perform an action, but it doe...
CVE-2024-37360MEDIUM4.4Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-...
CVE-2024-37359HIGH8.6The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but ...
CVE-2024-10339——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-53974MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-45777MEDIUM6.7A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_ge...
CVE-2024-52541HIGH8.2Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access cou...
CVE-2024-45084HIGH8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to con...
CVE-2024-45081MEDIUM6.5IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modif...
CVE-2024-28780MEDIUM5.9IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client  uses weaker than expected cr...
CVE-2024-28777HIGH8.8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserializat...
CVE-2024-28776MEDIUM5.4IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This ...
CVE-2024-52902HIGH8.8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded databas...
CVE-2024-13534HIGH7.5The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_i...
CVE-2024-13533HIGH7.5The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter ...
CVE-2024-13491HIGH7.5The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' ...
CVE-2024-13485HIGH7.5The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and '...
CVE-2024-13483HIGH7.5The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropshi...
CVE-2024-13481HIGH7.5The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and ...
CVE-2024-13479HIGH7.5The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and...
CVE-2024-13478HIGH7.5The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' a...
CVE-2024-13489HIGH7.5The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and ...
CVE-2024-13364MEDIUM5.3The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_...
CVE-2024-13363MEDIUM6.1The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all vers...
CVE-2024-13339MEDIUM5.4The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now