2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10239HIGH7.2A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with admin...
CVE-2024-10238HIGH7.2A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can uplo...
CVE-2024-10237HIGH7.2There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker ...
CVE-2024-13607MEDIUM4.3The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object ...
CVE-2024-12597MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'b...
CVE-2024-13332MEDIUM6.1The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13331MEDIUM6.1The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back...
CVE-2024-13330HIGH7.1The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13329HIGH7.1The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13328MEDIUM6.1The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-13327MEDIUM6.1The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13326MEDIUM6.1The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13325MEDIUM6.1The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-13115MEDIUM6.1The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places,...
CVE-2024-13114MEDIUM6.1The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter...
CVE-2024-47770HIGH8Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin...
CVE-2024-35177HIGH7.8Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin...
CVE-2024-57451HIGH7.5ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which ...
CVE-2024-56903HIGH8.1Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against ...
CVE-2024-56902HIGH7.5Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which ...
CVE-2024-56901HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less tha...
CVE-2024-56898HIGH8.8Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p...
CVE-2024-44449MEDIUM6.1Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive informat...
CVE-2024-34897HIGH7.5Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
CVE-2024-34896HIGH7.5An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected f...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now