2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43247HIGH8.8Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by AC...
CVE-2024-43401HIGH8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without ...
CVE-2024-43232HIGH8.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essent...
CVE-2024-43221HIGH8.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilde...
CVE-2024-42657HIGH7.5An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v...
CVE-2024-32927HIGH7.8In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to l...
CVE-2024-6348HIGH7.5Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Al...
CVE-2024-42633HIGH8.8A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.00...
CVE-2024-43380HIGH7.5fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5...
CVE-2024-6451HIGH7.2AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before...
CVE-2024-44083HIGH7.5ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump...
CVE-2024-44073HIGH7.5The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properl...
CVE-2024-44070HIGH7.5An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual rem...
CVE-2024-44069HIGH7.5Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dash...
CVE-2024-44067HIGH8.4The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions tha...
CVE-2024-7917HIGH7.2A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue...
CVE-2024-43315HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Ch...
CVE-2024-43288HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo F...
CVE-2024-43286HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly SEO Plugi...
CVE-2024-43282HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS....
CVE-2024-43279HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant N...
CVE-2024-43266HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue aff...
CVE-2024-43246HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon ...
CVE-2024-43244HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in favethemes ...
CVE-2024-43241HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now