2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1564MEDIUM4.3The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access cus...
CVE-2024-1232MEDIUM4.8The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac...
CVE-2024-1231MEDIUM6.8The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac...
CVE-2024-29071HIGH8.8HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at...
CVE-2024-28041HIGH8.8HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary comm...
CVE-2024-29188HIGH7.9WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action ...
CVE-2024-29187HIGH7.3WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs...
CVE-2024-29034MEDIUM6.1CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-...
CVE-2024-29194HIGH8.3OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation o...
CVE-2024-2856CRITICAL9.8A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by thi...
CVE-2024-2855CRITICAL9.8A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20. Affected by this vulner...
CVE-2024-2854CRITICAL9.8A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaCo...
CVE-2024-2853CRITICAL9.8A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. It has been rated as critical. This issue affects the ...
CVE-2024-2852CRITICAL9.8A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the...
CVE-2024-2851CRITICAL9.8A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the...
CVE-2024-2850CRITICAL9.8A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function s...
CVE-2024-30161MEDIUM6.5In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly ...
CVE-2024-30156HIGH7.5Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, all...
CVE-2024-24725HIGH8.8Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POS...
CVE-2024-23755HIGH8.8ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is in...
CVE-2024-1603HIGH7.5paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.
CVE-2024-2849CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Simple File Manager 1.0. This vulnerability affects u...
CVE-2024-24840MEDIUM5.4Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor ...
CVE-2024-24835MEDIUM6.5Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
CVE-2024-24832HIGH7.5Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now