2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0685CRITICAL9.8The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second...
CVE-2024-22533CRITICAL9.8Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incomi...
CVE-2024-22320HIGH8.8IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the sys...
CVE-2024-22319CRITICAL9.8 IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remo...
CVE-2024-23746CRITICAL9.8Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in ...
CVE-2024-22903HIGH8.8Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ...
CVE-2024-22902CRITICAL9.8Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
CVE-2024-22901CRITICAL9.8Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
CVE-2024-22900HIGH8.8Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ...
CVE-2024-22899HIGH8.8Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ...
CVE-2024-22779CRITICAL9.8Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbit...
CVE-2024-21399HIGH8.3Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-22096MEDIUM6.5In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to...
CVE-2024-22016HIGH7.8In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada ...
CVE-2024-21869MEDIUM5.5In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials i...
CVE-2024-21866MEDIUM5.3In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error me...
CVE-2024-21794MEDIUM5.4In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages t...
CVE-2024-21764CRITICAL9.8In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may ...
CVE-2024-24756HIGH7.5Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/`...
CVE-2024-23034MEDIUM6.1Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary c...
CVE-2024-23033MEDIUM6.1Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary co...
CVE-2024-23032MEDIUM6.1Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code vi...
CVE-2024-23031MEDIUM6.1Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitr...
CVE-2024-22927MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitr...
CVE-2024-21852HIGH8.8In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration fi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now