2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-53359HIGH7.5An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.
CVE-2024-55063HIGH8.8Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execut...
CVE-2024-13613HIGH7.5The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-53827HIGH7.5Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra...
CVE-2024-9831HIGH7.2The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL stateme...
CVE-2024-8700HIGH7.5The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthent...
CVE-2024-8699HIGH7.2The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users ...
CVE-2024-6719HIGH8.1The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which co...
CVE-2024-6486HIGH7.2The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec...
CVE-2024-12812HIGH7.5The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before...
CVE-2024-12735HIGH7.2The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL...
CVE-2024-11372HIGH7.2The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL stat...
CVE-2024-11269HIGH7.2The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statem...
CVE-2024-11267HIGH8.8The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL sta...
CVE-2024-0852HIGH8.8The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting i...
CVE-2024-0249HIGH7.1The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it...
CVE-2024-52880HIGH7.9An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-52879HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-52878HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-52877HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-13914HIGH7.2The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...
CVE-2024-45067HIGH8.2Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticat...
CVE-2024-55569HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2024-58101HIGH8.1Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to st...
CVE-2024-10864HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now