2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45352HIGH8.8An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by impro...
CVE-2024-45351HIGH7.8A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by imp...
CVE-2024-13889HIGH7.2The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ...
CVE-2024-13801HIGH8.1The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a ...
CVE-2024-13146HIGH8.8The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow att...
CVE-2024-31896HIGH7.5IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow...
CVE-2024-58105HIGH7.8A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ...
CVE-2024-58104HIGH7.8A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ...
CVE-2024-12169HIGH8.7A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allo...
CVE-2024-53678HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users ...
CVE-2024-13690HIGH7.2The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi...
CVE-2024-44903HIGH7.5SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is ava...
CVE-2024-13863HIGH7.1The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputt...
CVE-2024-13618HIGH7.2The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download....
CVE-2024-13617HIGH8.6The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unau...
CVE-2024-10210HIGH8.4An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an ...
CVE-2024-8313HIGH8.7An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an I...
CVE-2024-45484HIGH7.2An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used...
CVE-2024-45483HIGH7A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow ...
CVE-2024-45482HIGH8.5An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may a...
CVE-2024-45481HIGH8.5An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may all...
CVE-2024-10209HIGH8.5An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may ...
CVE-2024-8774HIGH7.7The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to e...
CVE-2024-8773HIGH8.3SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt...
CVE-2024-53350HIGH7.4Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escal...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now