2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35276CRITICAL9.8A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7...
CVE-2024-35275HIGH8.8A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version...
CVE-2024-35273HIGH8.8A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 al...
CVE-2024-33503HIGH7.8A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2...
CVE-2024-33502HIGH7.2An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyze...
CVE-2024-32115MEDIUM5.5A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 ...
CVE-2024-27778HIGH8.8An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo...
CVE-2024-26012HIGH7.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 a...
CVE-2024-23106CRITICAL9.8An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and...
CVE-2024-21758MEDIUM6.7A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri...
CVE-2024-11864HIGH7.5Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may l...
CVE-2024-11863MEDIUM5.3Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may l...
CVE-2024-11497HIGH8.8An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.
CVE-2024-56841CRITICAL9.1A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab...
CVE-2024-53649HIGH7.1A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC 5 6MD85 (CP300) (All ve...
CVE-2024-47100HIGH7.2A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 121...
CVE-2024-45385MEDIUM6.1A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vu...
CVE-2024-12240MEDIUM5.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label param...
CVE-2024-12919CRITICAL9.8The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2024-13156MEDIUM6.4The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-...
CVE-2024-11736MEDIUM4.9A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system ...
CVE-2024-11734MEDIUM6.5A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change...
CVE-2024-12365HIGH8.5The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o...
CVE-2024-12008HIGH7.5The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8....
CVE-2024-12006MEDIUM5.3The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now