2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-31145HIGH7.5Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reportin...
CVE-2024-8175HIGH7.5An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
CVE-2024-8290HIGH8.8The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is...
CVE-2024-8514HIGH7.2The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
CVE-2024-7385HIGH7.2The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers...
CVE-2024-8484HIGH7.5The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-jso...
CVE-2024-8481HIGH7.3The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an...
CVE-2024-8349HIGH7.2The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i...
CVE-2024-9123HIGH8.8Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds m...
CVE-2024-9122HIGH8.8Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory a...
CVE-2024-9121HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perf...
CVE-2024-9120HIGH8.8Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially explo...
CVE-2024-8942HIGH8.2Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input vali...
CVE-2024-8914HIGH7.2The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulner...
CVE-2024-8497HIGH8.7Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could...
CVE-2024-46936HIGH7.5Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation i...
CVE-2024-46935HIGH7.5Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers...
CVE-2024-46610HIGH7.5An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including...
CVE-2024-46609HIGH7.5An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticat...
CVE-2024-46607HIGH7.6Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values a...
CVE-2024-45373HIGH8.8Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.
CVE-2024-39928HIGH7.5In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the To...
CVE-2024-21545HIGH8.2Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient saf...
CVE-2024-8623HIGH7.3The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in al...
CVE-2024-8795HIGH8.8The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now