2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6030HIGH7Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to es...
CVE-2024-13943HIGH7.8Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil...
CVE-2024-9876HIGH8.5: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC...
CVE-2024-57698HIGH7.5An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with...
CVE-2024-13808HIGH8.8The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i...
CVE-2024-6199HIGH7.7An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS ...
CVE-2024-6198HIGH7.7The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the ...
CVE-2024-11917HIGH8.1The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ...
CVE-2024-33452HIGH7.7An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling v...
CVE-2024-46546HIGH7.3NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formF...
CVE-2024-40445HIGH7.3A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read ...
CVE-2024-11299HIGH7.5The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2024-13569HIGH7.1The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-46899HIGH7.1Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia...
CVE-2024-57394HIGH8.8The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore ...
CVE-2024-13926HIGH7.5The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain...
CVE-2024-42178HIGH7.5HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori...
CVE-2024-55211HIGH8.4An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.
CVE-2024-55238HIGH8.8OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2024-12530HIGH7Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.Thi...
CVE-2024-13925HIGH7.5The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint ...
CVE-2024-53305HIGH7.3An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supp...
CVE-2024-53303HIGH8.8A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al...
CVE-2024-22314HIGH7.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c...
CVE-2024-58093HIGH7.8In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstrea...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now