2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11974MEDIUM6.1The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_t...
CVE-2024-10932HIGH8.8The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1....
CVE-2024-55897MEDIUM4.3IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookie...
CVE-2024-55896MEDIUM5.4IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames.  This vuln...
CVE-2024-12237MEDIUM4.3The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in...
CVE-2024-11733HIGH7.3The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t...
CVE-2024-13129HIGH8.8A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is th...
CVE-2024-56332MEDIUM5.3Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions ...
CVE-2024-56412MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56411MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56410MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-36613MEDIUM6.2FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potent...
CVE-2024-35365HIGH8.8FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically...
CVE-2024-56514MEDIUM5.3Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes ...
CVE-2024-56513HIGH8.7Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes ...
CVE-2024-56409MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56366MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56365MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56408MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56324HIGH7.1GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edi...
CVE-2024-56322HIGH7.2GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hi...
CVE-2024-56321LOW3.8GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the ...
CVE-2024-56320HIGH8.8GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to i...
CVE-2024-55507CRITICAL9.8An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e...
CVE-2024-5591MEDIUM4.3IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detaile...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now