2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10476HIGH8Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be ab...
CVE-2024-37607MEDIUM6.5A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Servi...
CVE-2024-37606MEDIUM6.5A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (D...
CVE-2024-37605MEDIUM6.5A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service ...
CVE-2024-36832HIGH7.5A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via...
CVE-2024-36831MEDIUM5.3A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02...
CVE-2024-8972CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informati...
CVE-2024-9819MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse....
CVE-2024-54677MEDIUM5.3Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to den...
CVE-2024-50379CRITICAL9.8Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE o...
CVE-2024-10356MEDIUM4.3The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2024-9654LOW3.7The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T...
CVE-2024-8475MEDIUM6.5Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulati...
CVE-2024-8429MEDIUM4.3Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows ...
CVE-2024-52542MEDIUM5.5Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with...
CVE-2024-12601MEDIUM5.3The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including,...
CVE-2024-12395MEDIUM6.1The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-11280MEDIUM5.3The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u...
CVE-2024-8326HIGH8.8The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2024-12469MEDIUM6.1The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scri...
CVE-2024-12127MEDIUM6.1The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vu...
CVE-2024-12024MEDIUM6.1The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-12293HIGH8.8The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2024-11294MEDIUM5.3The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-12220MEDIUM6.1The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now