2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11686MEDIUM6.1The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts...
CVE-2024-11642CRITICAL9.8The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginatio...
CVE-2024-11328MEDIUM6.1The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ...
CVE-2024-13153MEDIUM5.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widg...
CVE-2024-12802CRITICAL9.1SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal ...
CVE-2024-43663CRITICAL9.8There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affect...
CVE-2024-43662MEDIUM5.3The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectiv...
CVE-2024-43661CRITICAL9.8The <redacted>.so library, which is used by <redacted>, is vulnerable to a buffer overflow in the code that handles the ...
CVE-2024-43660HIGH7.5The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware ...
CVE-2024-43659HIGH8.3After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default crede...
CVE-2024-43658HIGH7.2Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary fil...
CVE-2024-43657CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43656CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43655CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43654CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware...
CVE-2024-43653CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability  allows OS Command Inj...
CVE-2024-43652CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43651CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43650CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware ...
CVE-2024-43649CRITICAL9.3Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u...
CVE-2024-43648CRITICAL9.3Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use...
CVE-2024-40765CRITICAL9.8An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ...
CVE-2024-12806MEDIUM4.9A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an ar...
CVE-2024-12805HIGH7.2A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and...
CVE-2024-12803HIGH7.2A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now