2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57378HIGH7.3Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creati...
CVE-2024-11347HIGH7.3Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter module...
CVE-2024-11346HIGH7.3: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. A...
CVE-2024-11345HIGH7.3A heap-based memory vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vuln...
CVE-2024-11344HIGH7.3A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnera...
CVE-2024-12013HIGH7.6A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12...
CVE-2024-12012MEDIUM5.7A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway ...
CVE-2024-12011HIGH7.6A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The info...
CVE-2024-13182CRITICAL9.8The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu...
CVE-2024-13867MEDIUM6.1The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
CVE-2024-13606HIGH7.5The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information E...
CVE-2024-46910HIGH7.1An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas version...
CVE-2024-3303MEDIUM5.7An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior...
CVE-2024-13639MEDIUM4.3The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a miss...
CVE-2024-47266LOW2.7Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list function...
CVE-2024-47265MEDIUM6.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount f...
CVE-2024-47264MEDIUM6.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functional...
CVE-2024-13346CRITICAL9.8The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi...
CVE-2024-13345CRITICAL9.8The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi...
CVE-2024-13125LOW3.5The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-13121LOW3.5The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-13120MEDIUM4.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-13119MEDIUM4.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-12586MEDIUM6.1The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting ...
CVE-2024-10083MEDIUM6.8CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation whe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now