2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13948HIGH7.3Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informat...
CVE-2024-13947HIGH7.1Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become com...
CVE-2024-13946HIGH7.1DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting...
CVE-2024-9639HIGH8Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. Th...
CVE-2024-52874HIGH8.8In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.
CVE-2024-13931HIGH7.5Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials be...
CVE-2024-13929HIGH7.5Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become comp...
CVE-2024-13928HIGH7.5SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session adm...
CVE-2024-48850HIGH7.5Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue aff...
CVE-2024-25010HIGH8.8Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where imp...
CVE-2024-56429HIGH7.7itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users t...
CVE-2024-53359HIGH7.5An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.
CVE-2024-55063HIGH8.8Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execut...
CVE-2024-13613HIGH7.5The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-53827HIGH7.5Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra...
CVE-2024-9831HIGH7.2The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL stateme...
CVE-2024-8700HIGH7.5The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthent...
CVE-2024-8699HIGH7.2The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users ...
CVE-2024-6719HIGH8.1The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which co...
CVE-2024-6486HIGH7.2The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec...
CVE-2024-12812HIGH7.5The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before...
CVE-2024-12735HIGH7.2The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL...
CVE-2024-11372HIGH7.2The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL stat...
CVE-2024-11269HIGH7.2The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statem...
CVE-2024-11267HIGH8.8The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL sta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now