2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31144LOW3.8For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-over...
CVE-2024-8893HIGH7.3Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximi...
CVE-2024-57790MEDIUM5.4IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in ...
CVE-2024-56463MEDIUM4.8IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrar...
CVE-2024-3220LOW2.3There is a defect in the CPython standard library module “mimetypes” where on Windows the default list of known file loc...
CVE-2024-57778HIGH8.8An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the serv...
CVE-2024-57725MEDIUM6.5An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit...
CVE-2024-56973CRITICAL9.8Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker ...
CVE-2024-56477MEDIUM6.5IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the syst...
CVE-2024-52895MEDIUM6.5IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities res...
CVE-2024-56180CRITICAL9.8CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch wit...
CVE-2024-12651HIGH8.5Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variab...
CVE-2024-52500HIGH7.2Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly ...
CVE-2024-13152CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy...
CVE-2024-13791MEDIUM4.9Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down...
CVE-2024-52577CRITICAL9In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Igni...
CVE-2024-13735MEDIUM5.4The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ...
CVE-2024-9601MEDIUM5.4The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’...
CVE-2024-57969MEDIUM4.3app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.
CVE-2024-7052MEDIUM4.8The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allo...
CVE-2024-13692MEDIUM5.4The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature...
CVE-2024-13641HIGH7.5The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature...
CVE-2024-13493MEDIUM4.8The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could a...
CVE-2024-2240HIGH7.2Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authe...
CVE-2024-55904HIGH7.2IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now