2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56882MEDIUM5.4Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role pr...
CVE-2024-51505HIGH8An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race con...
CVE-2024-50609HIGH7.5An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP addre...
CVE-2024-50608HIGH7.5An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on a...
CVE-2024-4028LOW3.8A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the perm...
CVE-2024-49589MEDIUM6.5Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based...
CVE-2024-39328MEDIUM6.8Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their ...
CVE-2024-55460CRITICAL9.8A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election Syste...
CVE-2024-39327CRITICAL9.9Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing...
CVE-2024-57050——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11714. Reason: This candidate is a reservation d...
CVE-2024-57049——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2024-57046HIGH8.8A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individua...
CVE-2024-57045CRITICAL9.8A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals ...
CVE-2024-13689MEDIUM6.3The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including...
CVE-2024-13797CRITICAL9.8The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode ex...
CVE-2024-13783MEDIUM4.3The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in for...
CVE-2024-13691MEDIUM6.5The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_...
CVE-2024-13681HIGH7.5The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_...
CVE-2024-13667MEDIUM5.4The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all v...
CVE-2024-13636——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-24926. Reason: This candidate is a ...
CVE-2024-13369HIGH8.8The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘re...
CVE-2024-13718MEDIUM4.3The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-...
CVE-2024-13395MEDIUM5.4The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode...
CVE-2024-13316MEDIUM5.3The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin...
CVE-2024-12860CRITICAL9.8The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via accoun...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now