2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-42208LOW3.5HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in...
CVE-2024-42325LOW3.5Zabbix API user.get returns all users that share common group with the calling user. This includes media and other infor...
CVE-2024-36469LOW3.1Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.
CVE-2024-40864LOW2.7The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequ...
CVE-2024-55070LOW3.1A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allo...
CVE-2024-12683LOW3.5The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ...
CVE-2024-13123LOW3.5The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2024-13122LOW3.5The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2024-12769LOW3.5The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi...
CVE-2024-10560LOW3.5The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ...
CVE-2024-10554LOW3.5The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, whic...
CVE-2024-13124LOW3.5The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which coul...
CVE-2024-10558LOW3.5The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ...
CVE-2024-7598LOW3.1A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enf...
CVE-2024-7296LOW2.7An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 pr...
CVE-2024-13838LOW3.8The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2024-55592LOW3.8An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6....
CVE-2024-28607LOW2.9The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperl...
CVE-2024-13615LOW3.5The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin thr...
CVE-2024-41760LOW3.7IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due...
CVE-2024-54558LOW2.8A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS ...
CVE-2024-44179LOW2.4This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 1...
CVE-2024-52905LOW2.7IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitiv...
CVE-2024-12975LOW1A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet ov...
CVE-2024-11035LOW2.5Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a ty...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now