2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-38823LOW2.7Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
CVE-2024-38822LOW2.7Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another...
CVE-2024-7762LOW3.7The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthen...
CVE-2024-6711LOW3.5The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which ...
CVE-2024-4091LOW3.5The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which coul...
CVE-2024-4004LOW3.5The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could ...
CVE-2024-4002LOW3.5The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its set...
CVE-2024-3996LOW3.5The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow...
CVE-2024-12767LOW3.5The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view c...
CVE-2024-11140LOW3.5The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of i...
CVE-2024-10098LOW2.7The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing ...
CVE-2024-12533LOW3.3Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore Technology 4 allows Input Data ...
CVE-2024-58253LOW2.9In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to inva...
CVE-2024-30146LOW2.7Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server...
CVE-2024-47784LOW2.6Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in th...
CVE-2024-12273LOW3.5The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could...
CVE-2024-12706LOW2.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital ...
CVE-2024-9771LOW3.5The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-57375LOW2.4Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c...
CVE-2024-30127LOW3.2Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
CVE-2024-58251LOW2.5In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI t...
CVE-2024-11924LOW3.5The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape som...
CVE-2024-58249LOW3.7In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL.
CVE-2024-58248LOW3.5nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate red...
CVE-2024-58131LOW3.7FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a ma...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now