2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-52449HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Navneil Naicer Bootscrap...
CVE-2024-52448HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate ...
CVE-2024-52447HIGH8.6Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map a...
CVE-2024-52446HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM buying-buddy-idx-crm allows Object ...
CVE-2024-52445HIGH8.8Deserialization of Untrusted Data vulnerability in ModelTheme QRMenu Restaurant QR Menu Lite qrmenu-lite allows Object I...
CVE-2024-52444HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom P...
CVE-2024-52438HIGH8.8Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escala...
CVE-2024-52437HIGH8.8Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Pr...
CVE-2024-45690HIGH7.5A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts...
CVE-2024-10382HIGH7.5There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization l...
CVE-2024-11494HIGH7.5**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version...
CVE-2024-48895HIGH8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo...
CVE-2024-10900HIGH8.1The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2024-10899HIGH7.3The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio...
CVE-2024-10855HIGH8.1The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that...
CVE-2024-44308HIGH8.8The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18...
CVE-2024-44307HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma...
CVE-2024-44306HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma...
CVE-2024-51669HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Wi...
CVE-2024-52359HIGH8.8IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions ...
CVE-2024-45422HIGH7.5Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial o...
CVE-2024-45419HIGH7.5Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via...
CVE-2024-11395HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-51503HIGH8.8A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an at...
CVE-2024-21697HIGH8.8This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now