2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48416HIGH8.8Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClient...
CVE-2024-27256HIGH7.5IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 throu...
CVE-2024-45598MEDIUM4.9Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Po...
CVE-2024-38325HIGH7.5IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensi...
CVE-2024-38320HIGH7.5IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0...
CVE-2024-37527MEDIUM5.4IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated ...
CVE-2024-22316MEDIUM4.3IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perfo...
CVE-2024-57595CRITICAL9.8DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, whic...
CVE-2024-57590CRITICAL9.8TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",whi...
CVE-2024-11348MEDIUM5.3Eura7 CMSmanager in version 4.6 and below is vulnerable to Reflected XSS attacks through manipulation of return GET requ...
CVE-2024-55931MEDIUM6.5Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is...
CVE-2024-12345MEDIUM6.7A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknow...
CVE-2024-52012MEDIUM5.4Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary fil...
CVE-2024-43446LOW3.5An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even ...
CVE-2024-43445MEDIUM5.4A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-O...
CVE-2024-13117MEDIUM6.5The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and ...
CVE-2024-13116LOW3.8The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-13095MEDIUM4.8The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL st...
CVE-2024-13094HIGH7.1The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13057HIGH7.1The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-13056HIGH7.1The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back...
CVE-2024-13055HIGH7.1The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back...
CVE-2024-13052HIGH7.1The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before ...
CVE-2024-12774MEDIUM6.5The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-12773HIGH7.2The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL state...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now