2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-55952HIGH8.8DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JD...
CVE-2024-54383CRITICAL9.8Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege...
CVE-2024-54381HIGH7.1Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Men...
CVE-2024-49202HIGH7.6Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed ...
CVE-2024-49201MEDIUM4.3Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensit...
CVE-2024-47040HIGH7.8There is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no addit...
CVE-2024-47039MEDIUM5.5In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This...
CVE-2024-47038HIGH7.8In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds chec...
CVE-2024-55089MEDIUM4.1Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because ...
CVE-2024-55088HIGH8.8GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.
CVE-2024-55492MEDIUM6.1Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).
CVE-2024-55086HIGH7.2In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in downlo...
CVE-2024-45082MEDIUM5.2IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing...
CVE-2024-41752MEDIUM6.1IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker ...
CVE-2024-25042MEDIUM6.1IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripti...
CVE-2024-52361MEDIUM5.7IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be re...
CVE-2024-49576HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A spe...
CVE-2024-47810HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially craft...
CVE-2024-47119HIGH7.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow...
CVE-2024-12373CRITICAL9.3A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a b...
CVE-2024-12372CRITICAL9.3A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 100...
CVE-2024-12371CRITICAL9.3A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configur...
CVE-2024-56128MEDIUM5.3Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafk...
CVE-2024-50570MEDIUM5A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 th...
CVE-2024-48889HIGH7.2An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now