2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8950CRITICAL9.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics P...
CVE-2024-52046CRITICAL9.8The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized...
CVE-2024-12335MEDIUM4.3The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi...
CVE-2024-11281CRITICAL9.8The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and incl...
CVE-2024-10862MEDIUM4.9The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Injection ...
CVE-2024-10858MEDIUM6.1The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing...
CVE-2024-12636MEDIUM4.3The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul...
CVE-2024-12428HIGH7.5The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2024-1609HIGH8.7In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
CVE-2024-12413MEDIUM5.3The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorize...
CVE-2024-12272HIGH8.8The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPr...
CVE-2024-12190MEDIUM4.3The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-12032MEDIUM6.5The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin f...
CVE-2024-12746HIGH8.6A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privilege...
CVE-2024-12745HIGH8.6A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_sc...
CVE-2024-12744HIGH8.6A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSc...
CVE-2024-53163MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_420xx - fix off by one in uof_get_n...
CVE-2024-53162HIGH7.1In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_4xxx - fix off by one in uof_get_na...
CVE-2024-53161MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: EDAC/bluefield: Fix potential integer overflow The...
CVE-2024-53160MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: rcu/kvfree: Fix data-race in __mod_timer / kvfree_c...
CVE-2024-53159——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-53158MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: soc: qcom: geni-se: fix array underflow in geni_se_...
CVE-2024-53157MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: Check the DVFS OPP count return...
CVE-2024-53156HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: add range check for conn_rsp_epid in h...
CVE-2024-53155HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now