2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50640CRITICAL9.8jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function
CVE-2024-57157CRITICAL9.8Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a t...
CVE-2024-57491HIGH8.8Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to ac...
CVE-2024-39954MEDIUM6.3CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. ...
CVE-2024-12223CRITICAL9.3Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component...
CVE-2024-44373CRITICAL9.8A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create...
CVE-2024-45062MEDIUM6.8A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer tha...
CVE-2024-49827HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitiv...
CVE-2024-8393MEDIUM6.6The Woocommerce Blocks – Woolook plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2024-12612HIGH7.5The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters ac...
CVE-2024-12575MEDIUM5.3The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Expo...
CVE-2024-12573——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-24752 Reason: This candidate is a r...
CVE-2024-37945MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addo...
CVE-2024-53946HIGH8.8The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface....
CVE-2024-53945HIGH8.8The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSe...
CVE-2024-7402HIGH7Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamp...
CVE-2024-5477HIGH7.3A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escala...
CVE-2024-12303MEDIUM5.5An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18....
CVE-2024-10219MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18....
CVE-2024-52964MEDIUM6.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2024-48892MEDIUM4.9A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all vers...
CVE-2024-40588MEDIUM4.4Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiC...
CVE-2024-26009HIGH8.1An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6....
CVE-2024-33607MEDIUM5.6Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user...
CVE-2024-38805MEDIUM6.3EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A succe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now