2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54352HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Sabri Sogrid sogrid allows Privilege Escalation.This issue affects So...
CVE-2024-54332HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allow...
CVE-2024-54331HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree i-plant-a-tree allows Stored XSS.This issue affe...
CVE-2024-49775CRITICAL9.8A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence ...
CVE-2024-37251MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced...
CVE-2024-12668HIGH8.2Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user sp...
CVE-2024-12092MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE...
CVE-2024-12091MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER...
CVE-2024-12090MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE...
CVE-2024-12089MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER...
CVE-2024-10972HIGH7.3Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with...
CVE-2024-12478HIGH8.8A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the ...
CVE-2024-12362MEDIUM5.3A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function ...
CVE-2024-54682MEDIUM4.9Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size fo...
CVE-2024-54083MEDIUM6.5Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the ...
CVE-2024-48872MEDIUM4.8Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrent...
CVE-2024-9679MEDIUM5.3A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previousl...
CVE-2024-9678MEDIUM4.9An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arb...
CVE-2024-12646HIGH8.1The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local...
CVE-2024-12645MEDIUM6.5The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w...
CVE-2024-12644HIGH7.1The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web ser...
CVE-2024-12643HIGH8.1The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local ...
CVE-2024-12642HIGH8.1TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple loca...
CVE-2024-12641CRITICAL9.6TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a si...
CVE-2024-5333MEDIUM5.3The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now