2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-11299HIGH7.5The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2024-13569HIGH7.1The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-46899HIGH7.1Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia...
CVE-2024-57394HIGH8.8The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore ...
CVE-2024-13926HIGH7.5The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain...
CVE-2024-42178HIGH7.5HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori...
CVE-2024-55211HIGH8.4An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.
CVE-2024-55238HIGH8.8OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2024-12530HIGH7Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.Thi...
CVE-2024-13925HIGH7.5The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint ...
CVE-2024-53305HIGH7.3An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supp...
CVE-2024-53303HIGH8.8A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al...
CVE-2024-22314HIGH7.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c...
CVE-2024-58093HIGH7.8In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstrea...
CVE-2024-52281HIGH8.9A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to...
CVE-2024-42193HIGH8.1HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate valid...
CVE-2024-50960HIGH7.2A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351...
CVE-2024-36842HIGH7.3An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220...
CVE-2024-56406HIGH8.4A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, ...
CVE-2024-13861HIGH7.8A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3....
CVE-2024-52280HIGH7.7A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch ...
CVE-2024-11129HIGH7.5An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10...
CVE-2024-38865HIGH8.8Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0...
CVE-2024-13874HIGH7.1The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-55354HIGH8.8Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a prot...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now