2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54457HIGH7.2Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE102...
CVE-2024-53688HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmwa...
CVE-2024-47397HIGH7.5Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 an...
CVE-2024-39703HIGH8.8In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted...
CVE-2024-1610CRITICAL9.8In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
CVE-2024-12287CRITICAL9.8The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includin...
CVE-2024-11295MEDIUM5.3The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-56175MEDIUM6.1In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ...
CVE-2024-56174HIGH8.1In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ...
CVE-2024-56173MEDIUM4.7In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ...
CVE-2024-4464HIGH7.5Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-...
CVE-2024-21548HIGH7.5Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input s...
CVE-2024-21547HIGH7.7Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation i...
CVE-2024-21546CRITICAL9.8Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through ...
CVE-2024-10892MEDIUM5.4The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could a...
CVE-2024-56170MEDIUM5.3A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant ...
CVE-2024-56169MEDIUM5.3A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are ...
CVE-2024-12698MEDIUM6.5An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-4...
CVE-2024-12596MEDIUM4.3The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post del...
CVE-2024-12449MEDIUM6.4The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-12432HIGH8.1The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalati...
CVE-2024-12259HIGH8.8The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover i...
CVE-2024-12250MEDIUM5.3The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all...
CVE-2024-12061MEDIUM4.3The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc...
CVE-2024-12025HIGH7.5The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-js...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now