2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11452MEDIUM6.4The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-10789MEDIUM4.3The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-10970MEDIUM5.4The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution i...
CVE-2024-10401——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-57728HIGH7.2SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file s...
CVE-2024-57727HIGH7.5SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl...
CVE-2024-57726CRITICAL9.9SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to creat...
CVE-2024-55503LOW3.3An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_IN...
CVE-2024-53407LOW3.3In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially le...
CVE-2024-41454MEDIUM6.5An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-...
CVE-2024-41453MEDIUM4.8A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitr...
CVE-2024-39967MEDIUM6.5Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command...
CVE-2024-36751MEDIUM6.5An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL.
CVE-2024-48126CRITICAL9.8HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service...
CVE-2024-48125HIGH7.5An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via craft...
CVE-2024-48123HIGH8.4An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via u...
CVE-2024-48122MEDIUM6.7Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileg...
CVE-2024-48121MEDIUM6.5The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. Thi...
CVE-2024-54540MEDIUM4.3The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Proc...
CVE-2024-54535MEDIUM4.3A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia ...
CVE-2024-54470MEDIUM4.6A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPad...
CVE-2024-44136MEDIUM4.6This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...
CVE-2024-40854MEDIUM5.5A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS ...
CVE-2024-40839LOW2.4This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...
CVE-2024-40771HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now