2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2908MEDIUM4.3The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-2837MEDIUM5.4The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-2603MEDIUM6.3The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a...
CVE-2024-2439MEDIUM4.8The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a...
CVE-2024-2429MEDIUM4.3The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, wh...
CVE-2024-2310MEDIUM5.9The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could ...
CVE-2024-2159MEDIUM4.7The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes ...
CVE-2024-0905MEDIUM6.3The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it b...
CVE-2024-3154HIGH7.2A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can cr...
CVE-2024-32406HIGH7.5Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execut...
CVE-2024-32404MEDIUM6Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execut...
CVE-2024-22633CRITICAL9.8Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (...
CVE-2024-22632CRITICAL9.8Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (...
CVE-2024-4163HIGH8The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovere...
CVE-2024-31755HIGH7.6cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of func...
CVE-2024-33673HIGH7.8An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacki...
CVE-2024-33672HIGH7.1An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to...
CVE-2024-33671HIGH7.1An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded S...
CVE-2024-33670MEDIUM4.3Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a u...
CVE-2024-33669MEDIUM6.8An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned whil...
CVE-2024-33668CRITICAL9.1An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to id...
CVE-2024-33667MEDIUM6.5An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack b...
CVE-2024-33666HIGH8.6An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounti...
CVE-2024-33665MEDIUM6.1angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor ...
CVE-2024-33664MEDIUM5.3python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a cra...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now