2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31903HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on th...
CVE-2024-24429HIGH8.6A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of ...
CVE-2024-10929MEDIUM5.1In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may ...
CVE-2024-34235HIGH8.6Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the...
CVE-2024-24432MEDIUM5.3A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service...
CVE-2024-24430HIGH7.5A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv...
CVE-2024-13499HIGH7.3The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress...
CVE-2024-13496HIGH7.5The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2024-13495HIGH7.3The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress...
CVE-2024-13447MEDIUM4.3The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2024-13361HIGH8.8The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability che...
CVE-2024-13360MEDIUM5.4The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2024-13319MEDIUM6.1The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg...
CVE-2024-13406MEDIUM6.1The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id...
CVE-2024-12857CRITICAL9.8The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi...
CVE-2024-12117MEDIUM5.4The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-12879MEDIUM4.3The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2024-11218HIGH8.6A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 a...
CVE-2024-13590MEDIUM5.4The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' short...
CVE-2024-13584MEDIUM5.4The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-13426MEDIUM5.3The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2...
CVE-2024-13091CRITICAL9.8The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va...
CVE-2024-49749HIGH8.8In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remot...
CVE-2024-49748CRITICAL9.8In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflo...
CVE-2024-49747CRITICAL9.8In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the cod...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now