2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6482HIGH8.8The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ...
CVE-2024-8669HIGH7.2The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' ...
CVE-2024-8479HIGH7.3The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This ...
CVE-2024-8246HIGH8.8The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-8271HIGH7.3The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-44095HIGH7.8In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This co...
CVE-2024-44094HIGH7.8In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This...
CVE-2024-44093HIGH7.8In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This...
CVE-2024-44092HIGH7.8There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could l...
CVE-2024-29779HIGH7.8there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privile...
CVE-2024-8784HIGH8.8A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnera...
CVE-2024-8281HIGH7.2An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil...
CVE-2024-8280HIGH7.2An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil...
CVE-2024-8279HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate...
CVE-2024-8278HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate...
CVE-2024-39924HIGH8.8An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authen...
CVE-2024-6862HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive COR...
CVE-2024-45368HIGH8.8The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response pro...
CVE-2024-43099HIGH8.8The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions bet...
CVE-2024-31415HIGH8.1The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes su...
CVE-2024-6587HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows ...
CVE-2024-42025HIGH7.8A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (V...
CVE-2024-8242HIGH8.8The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uplo...
CVE-2024-7423HIGH8.8The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1....
CVE-2024-46713HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reporte...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now