2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53345HIGH8.8An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to ex...
CVE-2024-52813MEDIUM4.3matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust c...
CVE-2024-48245HIGH7.2Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in var...
CVE-2024-46603HIGH7.5An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows att...
CVE-2024-46602HIGH7.5An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) v...
CVE-2024-46601HIGH7.5Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.
CVE-2024-46242HIGH7.5An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a R...
CVE-2024-40702HIGH8.2IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid t...
CVE-2024-28778MEDIUM6.5IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys....
CVE-2024-25037MEDIUM4.3IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive ...
CVE-2024-11681MEDIUM6.9A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running por...
CVE-2024-45640MEDIUM5.3IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against...
CVE-2024-45100MEDIUM4.9IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration r...
CVE-2024-12738MEDIUM6.1The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2024-12426MEDIUM6.5Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document...
CVE-2024-12131MEDIUM4.3The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-52893MEDIUM5.3IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3  could allow a remote attacker to obtain sensitive informa...
CVE-2024-52891MEDIUM5.4IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious inf...
CVE-2024-52367HIGH7.5IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthori...
CVE-2024-52366MEDIUM5.9IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive informati...
CVE-2024-12711MEDIUM5.3The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec...
CVE-2024-12532MEDIUM4.3The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
CVE-2024-12425LOW3.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation ...
CVE-2024-12316MEDIUM5.3The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o...
CVE-2024-12033MEDIUM4.3The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sy...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now