2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50585MEDIUM4.7Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary J...
CVE-2024-51460MEDIUM4.3IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed...
CVE-2024-11351MEDIUM5.3The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable t...
CVE-2024-12325MEDIUM6.1The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all vers...
CVE-2024-12294MEDIUM5.3The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2024-11840HIGH7.1The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and ...
CVE-2024-11008MEDIUM5.3The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2024-54269MEDIUM4.3Missing Authorization vulnerability in Ninja Team Notibar notibar allows Exploiting Incorrectly Configured Access Contro...
CVE-2024-12363HIGH7.1Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a...
CVE-2024-11737CRITICAL9.8CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidential...
CVE-2024-11401MEDIUM5.3Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, ...
CVE-2024-12283MEDIUM6.1The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions...
CVE-2024-12004MEDIUM6.1The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2024-10511MEDIUM6.3CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someon...
CVE-2024-53292MEDIUM6.7Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A l...
CVE-2024-53290HIGH8.4Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection')...
CVE-2024-53289HIGH7Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged at...
CVE-2024-52537MEDIUM6.7Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attac...
CVE-2024-11053LOW3.4When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used f...
CVE-2024-35117MEDIUM4.4IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the syste...
CVE-2024-55655LOW2.7sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer tha...
CVE-2024-55653MEDIUM6.5PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to c...
CVE-2024-54133LOW2.3Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) v...
CVE-2024-53960MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-53959HIGH7.8Adobe Framemaker versions 2020.7, 2022.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now