2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8936HIGH8.3CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory a...
CVE-2024-8935HIGH7.7CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confide...
CVE-2024-10800HIGH8.8The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability c...
CVE-2024-8933HIGH7.5CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t...
CVE-2024-10816HIGH7.5The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6....
CVE-2024-10174HIGH7.3The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-39709HIGH7.8Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Se...
CVE-2024-38655HIGH7.2Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version...
CVE-2024-38649HIGH7.5An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remot...
CVE-2024-37400HIGH7.5An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigg...
CVE-2024-37398HIGH7.8Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate t...
CVE-2024-37376HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-34787HIGH7.8Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-34784HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-34782HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-34781HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-34780HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-32847HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-32844HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-32841HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-32839HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-10629HIGH8.8The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file ...
CVE-2024-28726HIGH8An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to e...
CVE-2024-51179HIGH7.5An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizati...
CVE-2024-51094HIGH8An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a mal...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now