2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6477HIGH7.5The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could all...
CVE-2024-3056HIGH7.7A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur...
CVE-2024-38891HIGH7.5An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-42348HIGH8.6FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and passw...
CVE-2024-28298HIGH8.8SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands v...
CVE-2024-28297HIGH7.5SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via ...
CVE-2024-22169HIGH7.1WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow c...
CVE-2024-38885HIGH7.5An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38884HIGH7.8An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38881HIGH7.5An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-33896HIGH7.2Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due...
CVE-2024-33894HIGH8.8Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3...
CVE-2024-33892HIGH7.5Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s...
CVE-2024-41518HIGH7.5An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allow...
CVE-2024-41310HIGH7.5AndServer 2.1.12 is vulnerable to Directory Traversal.
CVE-2024-38890HIGH8.4An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later version...
CVE-2024-40721HIGH8.8The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-...
CVE-2024-40720HIGH8.8The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-...
CVE-2024-38877HIGH8.8A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont...
CVE-2024-38876HIGH7.8A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont...
CVE-2024-27181HIGH8.8In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted ac...
CVE-2024-38776HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This i...
CVE-2024-3238HIGH8.8The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2024-39392HIGH7.8InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c...
CVE-2024-7389HIGH7.5The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now