2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54446HIGH7.1Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a ...
CVE-2024-54445HIGH8.7Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-base...
CVE-2024-12245HIGH8.7Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-bas...
CVE-2024-12019HIGH7.1The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read...
CVE-2024-46662HIGH8.8A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions ...
CVE-2024-45643HIGH7.5IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt ...
CVE-2024-13773HIGH7.5The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information...
CVE-2024-12810HIGH8.1The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat...
CVE-2024-8176HIGH7.5A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XM...
CVE-2024-13913HIGH8.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2024-13376HIGH8.8The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat...
CVE-2024-11283HIGH7.5The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th...
CVE-2024-55549HIGH7.8xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.
CVE-2024-53406HIGH8.8Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection p...
CVE-2024-10942HIGH7.5The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,...
CVE-2024-8402HIGH7.4An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from...
CVE-2024-13891HIGH7.1The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13885HIGH7.1The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-13884HIGH7.1The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-12380HIGH7.5An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f...
CVE-2024-26290HIGH8.7Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Av...
CVE-2024-13872HIGH7.5Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Int...
CVE-2024-13871HIGH8.8A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (fir...
CVE-2024-58087HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expir...
CVE-2024-9157HIGH7.8** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now