2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12600HIGH7.2The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions ...
CVE-2024-10552MEDIUM6.4The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘api_key’ and 'api_sec...
CVE-2024-13721MEDIUM6.4The Plethora Plugins Tabs + Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the anchor ...
CVE-2024-13709MEDIUM4.3The Linear plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1....
CVE-2024-50698CRITICAL9.8SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of...
CVE-2024-50697HIGH8.1In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TL...
CVE-2024-50695CRITICAL9.8SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT mess...
CVE-2024-50694CRITICAL9.8In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the under...
CVE-2024-50692MEDIUM5.4SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send ...
CVE-2024-50690MEDIUM6.5SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmw...
CVE-2024-57277MEDIUM5.7InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2024-57095MEDIUM6.8SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2024-57041MEDIUM4.6A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code ...
CVE-2024-52807HIGH8.6The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT ...
CVE-2024-56404CRITICAL9.9In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privile...
CVE-2024-35122LOW2.8IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority r...
CVE-2024-45077MEDIUM6.5IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated ...
CVE-2024-41757MEDIUM5.9IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failur...
CVE-2024-40706MEDIUM4.3IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid ...
CVE-2024-40693HIGH8IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the fil...
CVE-2024-25034HIGH8.8IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in th...
CVE-2024-13698MEDIUM6.5The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due t...
CVE-2024-9499HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lea...
CVE-2024-9498HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to p...
CVE-2024-9497HIGH8.6DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now