2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-12281CRITICAL9.8The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is...
CVE-2024-11951CRITICAL9.8The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including...
CVE-2024-13787CRITICAL9.8The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to,...
CVE-2024-13777CRITICAL9.8The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in...
CVE-2024-41147CRITICAL9.8An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio ...
CVE-2024-50707CRITICAL10Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to exec...
CVE-2024-50704CRITICAL10Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to exec...
CVE-2024-11957CRITICAL9.3Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12...
CVE-2024-50706CRITICAL9.8Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbi...
CVE-2024-55532CRITICAL9.8Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Use...
CVE-2024-8262CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allo...
CVE-2024-47092CRITICAL9.8Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1
CVE-2024-12824CRITICAL9.8The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in ...
CVE-2024-1509CRITICAL9.1Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response h...
CVE-2024-9193CRITICAL9.8The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers...
CVE-2024-8425CRITICAL9.8The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file...
CVE-2024-8420CRITICAL9.8The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. Th...
CVE-2024-37567CRITICAL9.1Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.
CVE-2024-37566CRITICAL9.8Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
CVE-2024-36047CRITICAL9.8Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.
CVE-2024-36046CRITICAL9.8Infoblox NIOS through 8.6.4 executes with more privileges than required.
CVE-2024-38292CRITICAL9.8In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which ma...
CVE-2024-55160CRITICAL9.8GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/op...
CVE-2024-51139CRITICAL9.8Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862...
CVE-2024-51138CRITICAL9.8Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now