2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13752MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-12562CRITICAL9.8The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216...
CVE-2024-13563MEDIUM5.4The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s...
CVE-2024-13525MEDIUM6.5The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2024-13513CRITICAL9.8The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2024-13306MEDIUM4.3The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ...
CVE-2024-13208MEDIUM4.3The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ...
CVE-2024-37375Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13843.
CVE-2024-37374Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13842.
CVE-2024-5462HIGH7.5If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP ...
CVE-2024-5461HIGH8Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch...
CVE-2024-4282CRITICAL9.8Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
CVE-2024-10405MEDIUM5.3Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, ...
CVE-2024-31144LOW3.8For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-over...
CVE-2024-8893HIGH7.3Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximi...
CVE-2024-57790MEDIUM5.4IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in ...
CVE-2024-56463MEDIUM4.8IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrar...
CVE-2024-3220LOW2.3There is a defect in the CPython standard library module “mimetypes” where on Windows the default list of known file loc...
CVE-2024-57778HIGH8.8An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the serv...
CVE-2024-57725MEDIUM6.5An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit...
CVE-2024-56973CRITICAL9.8Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker ...
CVE-2024-56477MEDIUM6.5IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the syst...
CVE-2024-52895MEDIUM6.5IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities res...
CVE-2024-56180CRITICAL9.8CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch wit...
CVE-2024-12651HIGH8.5Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variab...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now