2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56924HIGH7.3A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to...
CVE-2024-56923MEDIUM5.4Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silver...
CVE-2024-56914MEDIUM5.7D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.
CVE-2024-9310MEDIUM6By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data...
CVE-2024-11166HIGH7.1For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a grou...
CVE-2024-55957HIGH7.8In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 ...
CVE-2024-51457MEDIUM5.4IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-...
CVE-2024-55488MEDIUM6.5A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scrip...
CVE-2024-42013MEDIUM6.4In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attac...
CVE-2024-42012MEDIUM5.7GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is c...
CVE-2024-31903HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on th...
CVE-2024-24429HIGH8.6A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of ...
CVE-2024-10929MEDIUM5.1In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may ...
CVE-2024-34235HIGH8.6Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the...
CVE-2024-24432MEDIUM5.3A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service...
CVE-2024-24430HIGH7.5A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv...
CVE-2024-13499HIGH7.3The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress...
CVE-2024-13496HIGH7.5The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2024-13495HIGH7.3The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress...
CVE-2024-13447MEDIUM4.3The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2024-13361HIGH8.8The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability che...
CVE-2024-13360MEDIUM5.4The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2024-13319MEDIUM6.1The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg...
CVE-2024-13406MEDIUM6.1The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id...
CVE-2024-12857CRITICAL9.8The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now