2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11950HIGH8.8XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-11949HIGH8.8GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-11948CRITICAL9.8GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a...
CVE-2024-11947HIGH8.8GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2024-11872HIGH7.8Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows lo...
CVE-2024-9845HIGH7.8Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authent...
CVE-2024-8496HIGH7.8Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local ...
CVE-2024-48912HIGH8.1GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an aut...
CVE-2024-47761HIGH7.2GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an admin...
CVE-2024-47760HIGH8.8GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a techn...
CVE-2024-11598HIGH7.8Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, ...
CVE-2024-11597HIGH7.8Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, ...
CVE-2024-10251HIGH7.8Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local au...
CVE-2024-53677CRITICAL9.8File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal an...
CVE-2024-47758HIGH8.8GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an auth...
CVE-2024-28141MEDIUM6.3The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users ...
CVE-2024-28140MEDIUM6.1The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser...
CVE-2024-28139HIGH8.8The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as r...
CVE-2024-50585MEDIUM4.7Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary J...
CVE-2024-51460MEDIUM4.3IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed...
CVE-2024-11351MEDIUM5.3The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable t...
CVE-2024-12325MEDIUM6.1The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all vers...
CVE-2024-12294MEDIUM5.3The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2024-11840HIGH7.1The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and ...
CVE-2024-11008MEDIUM5.3The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now