2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12708HIGH7.1The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outpu...
CVE-2024-12638HIGH7.1The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-12400HIGH7.1The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leadin...
CVE-2024-12163MEDIUM6.5The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containin...
CVE-2024-10309MEDIUM5.9The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when o...
CVE-2024-57665CRITICAL9.8JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability...
CVE-2024-57513MEDIUM6.5A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.
CVE-2024-57510HIGH7.8Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex...
CVE-2024-57509HIGH7.8Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex...
CVE-2024-57395CRITICAL9.8Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileg...
CVE-2024-54852CRITICAL9.8When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnera...
CVE-2024-54851HIGH8.8Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.
CVE-2024-51182MEDIUM6.1HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML c...
CVE-2024-48761HIGH8.8Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScr...
CVE-2024-23733HIGH7.5The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core...
CVE-2024-12705HIGH7.5Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or i...
CVE-2024-11187HIGH7.5It is possible to construct a zone such that some queries to it will generate responses containing numerous records in t...
CVE-2024-48852CRITICAL9.4Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly di...
CVE-2024-48849CRITICAL9.4Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauth...
CVE-2024-10001HIGH7.1A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious cod...
CVE-2024-57439MEDIUM4.9An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Ser...
CVE-2024-57438MEDIUM5.4Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves highe...
CVE-2024-57437MEDIUM6.5RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.
CVE-2024-57436HIGH7.2RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring...
CVE-2024-54462HIGH7.1The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now