2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-3983HIGH8.1The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which cou...
CVE-2024-7338HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the...
CVE-2024-6698HIGH8.8The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. T...
CVE-2024-7337HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by...
CVE-2024-7336HIGH8.8A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability...
CVE-2024-7335HIGH8.8A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function ...
CVE-2024-7334HIGH8.8A vulnerability was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. It has been rated as critical. This issue affects t...
CVE-2024-7333HIGH8.8A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability...
CVE-2024-6687HIGH7.5The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions u...
CVE-2024-40883HIGH8.8Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging i...
CVE-2024-7331HIGH8.8A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue i...
CVE-2024-7327HIGH8.8A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataActi...
CVE-2024-41262HIGH7.4mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly all...
CVE-2024-7326HIGH7.8A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknow...
CVE-2024-41255HIGH7.5filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attack...
CVE-2024-41253HIGH7.1goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-m...
CVE-2024-40465HIGH8.8An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function i...
CVE-2024-40464HIGH8.8An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located i...
CVE-2024-7325HIGH7.8A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is som...
CVE-2024-41954HIGH7.8FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account cred...
CVE-2024-41630HIGH7.6Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary cod...
CVE-2024-40645HIGH8.8FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows a...
CVE-2024-7324HIGH8.5A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this ...
CVE-2024-23444HIGH7.5It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order ...
CVE-2024-6978HIGH8.8Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now