2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13617HIGH8.6The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unau...
CVE-2024-10210HIGH8.4An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an ...
CVE-2024-8313HIGH8.7An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an I...
CVE-2024-45484HIGH7.2An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used...
CVE-2024-45483HIGH7A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow ...
CVE-2024-45482HIGH8.5An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may a...
CVE-2024-45481HIGH8.5An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may all...
CVE-2024-10209HIGH8.5An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may ...
CVE-2024-8774HIGH7.7The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to e...
CVE-2024-8773HIGH8.3SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt...
CVE-2024-53350HIGH7.4Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escal...
CVE-2024-53349HIGH7.4Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escal...
CVE-2024-53348HIGH7.4LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive informati...
CVE-2024-57490HIGH7.7Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system ...
CVE-2024-13903HIGH7.5A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulne...
CVE-2024-54551HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, mac...
CVE-2024-44305HIGH7.8This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able t...
CVE-2024-44199HIGH7.1An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may...
CVE-2024-57440HIGH7.5D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webpr...
CVE-2024-13921HIGH7.2The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio...
CVE-2024-9920HIGH8.8In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, ...
CVE-2024-9919HIGH8.4A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauth...
CVE-2024-9847HIGH8FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable...
CVE-2024-9606HIGH7.5In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerabi...
CVE-2024-9597HIGH7.1A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now