2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13880HIGH7.1The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13878HIGH7.1The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13877HIGH7.1The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before ou...
CVE-2024-13876HIGH7.1The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13875HIGH7.1The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-51459HIGH7.8IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handl...
CVE-2024-42176HIGH8HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous ...
CVE-2024-55551HIGH8.3An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into...
CVE-2024-13933HIGH8.8The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request F...
CVE-2024-12920HIGH8.8The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access ...
CVE-2024-12137HIGH7.6Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. T...
CVE-2024-12136HIGH7.8Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass...
CVE-2024-13412HIGH7.5The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-50631HIGH7.5Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing...
CVE-2024-50630HIGH7.5Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4...
CVE-2024-12295HIGH8.8The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers...
CVE-2024-10444HIGH7.5Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-4...
CVE-2024-12563HIGH8.8The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214...
CVE-2024-44313HIGH8.1TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which ...
CVE-2024-21760HIGH8.4An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4...
CVE-2024-23942HIGH7.1A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an att...
CVE-2024-40635HIGH7.8containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0....
CVE-2024-54525HIGH8.8A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia ...
CVE-2024-44276HIGH7.3This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and i...
CVE-2024-49561HIGH7.8Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Ass...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now