2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8480HIGH8.8The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due ...
CVE-2024-8247HIGH8.8The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2...
CVE-2024-42495HIGH7.5Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow...
CVE-2024-7591HIGH7.2Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMa...
CVE-2024-45401HIGH7.1stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in ver...
CVE-2024-45175HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It...
CVE-2024-45171HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos...
CVE-2024-45098HIGH8.1IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource mod...
CVE-2024-45097HIGH7.1IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource mod...
CVE-2024-45178HIGH7.1An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos...
CVE-2024-45173HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning ...
CVE-2024-44587HIGH8.8itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.
CVE-2024-8470HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /j...
CVE-2024-8469HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobport...
CVE-2024-8468HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /job...
CVE-2024-8467HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobport...
CVE-2024-8466HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /j...
CVE-2024-8465HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jo...
CVE-2024-8464HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /j...
CVE-2024-8463HIGH8.8File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an auth...
CVE-2024-7884HIGH7.5When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the calle...
CVE-2024-5957HIGH7.5This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
CVE-2024-8178HIGH8.8The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it...
CVE-2024-45063HIGH8.8The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished p...
CVE-2024-43110HIGH8.8The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software runni...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now