2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43650CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware ...
CVE-2024-43649CRITICAL9.3Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u...
CVE-2024-43648CRITICAL9.3Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use...
CVE-2024-40765CRITICAL9.8An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ...
CVE-2024-12806MEDIUM4.9A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an ar...
CVE-2024-12805HIGH7.2A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and...
CVE-2024-12803HIGH7.2A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash ...
CVE-2024-53706HIGH7.8A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to e...
CVE-2024-53705HIGH7.5A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establis...
CVE-2024-53704CRITICAL9.8An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe...
CVE-2024-40762CRITICAL9.8Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator...
CVE-2024-13041MEDIUM5.4An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 pr...
CVE-2024-6324MEDIUM4.3An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 pr...
CVE-2024-12736MEDIUM6.1The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back...
CVE-2024-12731MEDIUM6.1The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-12717MEDIUM4.8The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow...
CVE-2024-12715MEDIUM6.1The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it b...
CVE-2024-12714MEDIUM6.1The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputtin...
CVE-2024-10815MEDIUM4.2The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it ...
CVE-2024-56827MEDIUM5.6A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are spe...
CVE-2024-56826MEDIUM5.6A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are spe...
CVE-2024-13213MEDIUM5.4A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of ...
CVE-2024-13212HIGH8.8A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/up...
CVE-2024-13211HIGH8.8A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown...
CVE-2024-13210HIGH7.2A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnera...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now