2024 CVE Vulnerabilities

39,152 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-58253LOW2.9In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to inva...
CVE-2024-30146LOW2.7Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server...
CVE-2024-47784LOW2.1Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in th...
CVE-2024-12273LOW3.5The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could...
CVE-2024-12706LOW2.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital ...
CVE-2024-9771LOW3.5The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-57375LOW2.4Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c...
CVE-2024-30127LOW3.2Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
CVE-2024-58251LOW2.5In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI t...
CVE-2024-11924LOW3.5The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape som...
CVE-2024-58249LOW3.7In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL.
CVE-2024-58248LOW3.5nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate red...
CVE-2024-42193LOW2.1HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate valid...
CVE-2024-49709LOW2.3Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attack...
CVE-2024-58131LOW3.7FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a ma...
CVE-2024-42208LOW3.5HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in...
CVE-2024-42325LOW2.1Zabbix API user.get returns all users that share common group with the calling user. This includes media and other infor...
CVE-2024-36469LOW2.3Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.
CVE-2024-40864LOW2.7The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequ...
CVE-2024-39311LOW1.8Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions...
CVE-2024-55070LOW3.1A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allo...
CVE-2024-12683LOW3.5The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ...
CVE-2024-13123LOW3.5The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2024-13122LOW3.5The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2024-12769LOW3.5The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now