2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-48615HIGH7.5Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pa...
CVE-2024-7407HIGH8.2Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords ...
CVE-2024-11504HIGH8.6Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, w...
CVE-2024-13939HIGH7.5String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the...
CVE-2024-49565HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-49564HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-49563HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-55073HIGH7.6A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ...
CVE-2024-12905HIGH7.5An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted ...
CVE-2024-9773HIGH8An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from...
CVE-2024-45356HIGH7.3A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida...
CVE-2024-45352HIGH8.8An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by impro...
CVE-2024-45351HIGH7.8A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by imp...
CVE-2024-13889HIGH7.2The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ...
CVE-2024-13801HIGH8.1The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a ...
CVE-2024-13146HIGH8.8The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow att...
CVE-2024-31896HIGH7.5IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow...
CVE-2024-58105HIGH7.8A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ...
CVE-2024-58104HIGH7.8A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ...
CVE-2024-12169HIGH8.7A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allo...
CVE-2024-53678HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users ...
CVE-2024-13690HIGH7.2The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi...
CVE-2024-44903HIGH7.5SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is ava...
CVE-2024-13863HIGH7.1The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputt...
CVE-2024-13618HIGH7.2The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now