2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12171HIGH8.8The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due t...
CVE-2024-11780MEDIUM5.4The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultbloc...
CVE-2024-57587CRITICAL9.1Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated ...
CVE-2024-57435MEDIUM6.5In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a nul...
CVE-2024-57434HIGH8.8macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test...
CVE-2024-57433HIGH7.5macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, the...
CVE-2024-55062CRITICAL9.8Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers ...
CVE-2024-53357HIGH7.5Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated at...
CVE-2024-53356CRITICAL9.8Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JW...
CVE-2024-53355HIGH8.8Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated ...
CVE-2024-53354MEDIUM6.5Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated at...
CVE-2024-57432HIGH7.5macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do no...
CVE-2024-53584CRITICAL9.8OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
CVE-2024-49349MEDIUM5.4IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored ...
CVE-2024-49339MEDIUM5.4IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored ...
CVE-2024-47857CRITICAL9.8SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures w...
CVE-2024-42671MEDIUM6.1A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirec...
CVE-2024-53582HIGH7.5An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec...
CVE-2024-53537CRITICAL9.1An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager...
CVE-2024-53320CRITICAL9.8Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveC...
CVE-2024-53319HIGH7.5A heap buffer overflow in the XML Text Escaping component of Qualisys C++ SDK commit a32a21a allows attackers to cause D...
CVE-2024-49807MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored...
CVE-2024-47116MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-...
CVE-2024-47103MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-...
CVE-2024-45089MEDIUM4.3IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now