2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47038HIGH7.8In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds chec...
CVE-2024-55089MEDIUM4.1Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because ...
CVE-2024-55088HIGH8.8GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.
CVE-2024-55492MEDIUM6.1Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).
CVE-2024-55086HIGH7.2In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in downlo...
CVE-2024-45082MEDIUM5.2IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing...
CVE-2024-41752MEDIUM6.1IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker ...
CVE-2024-25042MEDIUM6.1IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripti...
CVE-2024-52361MEDIUM5.7IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be re...
CVE-2024-49576HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A spe...
CVE-2024-47810HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially craft...
CVE-2024-47119HIGH7.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow...
CVE-2024-12373CRITICAL9.3A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a b...
CVE-2024-12372CRITICAL9.3A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 100...
CVE-2024-12371CRITICAL9.3A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configur...
CVE-2024-56128MEDIUM5.3Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafk...
CVE-2024-50570MEDIUM5A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 th...
CVE-2024-48889HIGH7.2An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-56059CRITICAL9.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Pa...
CVE-2024-56058CRITICAL9.8Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.Th...
CVE-2024-56016HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maartenhemmes Imag...
CVE-2024-56010HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Devi...
CVE-2024-56008HIGH7.5Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality...
CVE-2024-55997MEDIUM6.5Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-locati...
CVE-2024-55985HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YD...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now