2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56328MEDIUM6.1Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' br...
CVE-2024-56197MEDIUM4.9Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when th...
CVE-2024-55948HIGH8.2Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR re...
CVE-2024-45658MEDIUM5.3IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti...
CVE-2024-45657MEDIUM6.7IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform ...
CVE-2024-43187HIGH7.5IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data i...
CVE-2024-40700MEDIUM6.1IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vul...
CVE-2024-35138MEDIUM6.5IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery whi...
CVE-2024-48019MEDIUM5.4Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to Exter...
CVE-2024-45659MEDIUM5.3IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti...
CVE-2024-9644CRITICAL9.8The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the admini...
CVE-2024-9643CRITICAL9.8The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials i...
CVE-2024-23690HIGH7.2The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac...
CVE-2024-11623MEDIUM4.8Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application i...
CVE-2024-13699MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter...
CVE-2024-27137MEDIUM5.3In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration...
CVE-2024-40891HIGH8.8**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le...
CVE-2024-40890HIGH8.8**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL...
CVE-2024-13733MEDIUM5.4The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-13529MEDIUM6.5The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of ...
CVE-2024-13510MEDIUM6.1The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5....
CVE-2024-13356MEDIUM6.5The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-13403MEDIUM5.4The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2024-13514MEDIUM4.3The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions u...
CVE-2024-12046MEDIUM4.3The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now