2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11839HIGH7.5Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitra...
CVE-2024-11838CRITICAL9.8External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocument...
CVE-2024-11837CRITICAL9.8Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac  allows...
CVE-2024-11836HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue a...
CVE-2024-11835HIGH7.5Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61....
CVE-2024-11834CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrar...
CVE-2024-11833CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrar...
CVE-2024-10939MEDIUM4.8The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which co...
CVE-2024-10678MEDIUM5.4The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputt...
CVE-2024-21544HIGH8.6Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL ...
CVE-2024-21543HIGH7.1Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fai...
CVE-2024-12579MEDIUM5.3The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to...
CVE-2024-12574MEDIUM5.4The SVG Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-11809MEDIUM6.1The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src'...
CVE-2024-11767MEDIUM6.4The NewsmanApp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'newsman_subscribe_wid...
CVE-2024-12572MEDIUM6.1The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-12300LOW3.7The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca...
CVE-2024-12603CRITICAL9.8A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application passwo...
CVE-2024-9508HIGH8.5Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose informat...
CVE-2024-12212HIGH8.5The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supp...
CVE-2024-12289MEDIUM5.9Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initializati...
CVE-2024-55888HIGH7.1Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the p...
CVE-2024-55886MEDIUM6.9OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes...
CVE-2024-55885HIGH7.5beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a has...
CVE-2024-55879HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now