2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31372MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Arnan de Gans No-Bot Registration.This issue affects No-Bot Registrat...
CVE-2024-31371MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Xylus Themes WP Event Aggregator.This issue affects WP Event Aggregat...
CVE-2024-3400CRITICAL10A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Netwo...
CVE-2024-29400HIGH7.5An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.
CVE-2024-27309HIGH7.4While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correc...
CVE-2024-22526MEDIUM5.5Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via...
CVE-2024-30850Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-33434. Reason: This record is a duplicate of CVE-2024-...
CVE-2024-30614MEDIUM5.3An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the e...
CVE-2024-22734MEDIUM6.2An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attack...
CVE-2024-2801MEDIUM6.4The Shopkeeper Extender plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_slide'...
CVE-2024-2137MEDIUM5.4The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mu...
CVE-2024-22357MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc...
CVE-2024-3092MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions start...
CVE-2024-2279MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting f...
CVE-2024-28458HIGH7.5Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the fun...
CVE-2024-27592MEDIUM4.3Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via app...
CVE-2024-25852HIGH8.8Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter ...
CVE-2024-25376HIGH7.8An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a l...
CVE-2024-29454Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-22722HIGH7.2Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via t...
CVE-2024-22721MEDIUM6.3Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data v...
CVE-2024-22719HIGH8.1SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when se...
CVE-2024-22718CRITICAL9.6Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id pa...
CVE-2024-22717MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name f...
CVE-2024-30273HIGH7.8Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could res...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now