2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12350HIGH8.8A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update...
CVE-2024-12349HIGH8.8A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an un...
CVE-2024-12348MEDIUM6.1A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is ...
CVE-2024-12347MEDIUM6.9A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This ...
CVE-2024-12346MEDIUM5.3A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unk...
CVE-2024-55560CRITICAL9.8MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persi...
CVE-2024-12344CRITICAL9.8A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unkno...
CVE-2024-12343HIGH8.8A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown funct...
CVE-2024-12342HIGH7.1A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some u...
CVE-2024-12209CRITICAL9.8The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all ve...
CVE-2024-53473HIGH7.5WeGIA 3.2.0 before 3998672 does not verify permission to change a password.
CVE-2024-47107MEDIUM5.4IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed...
CVE-2024-41762MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2024-47115HIGH7.8IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improp...
CVE-2024-37071MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user...
CVE-2024-11501HIGH8.8The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via des...
CVE-2024-11464MEDIUM6.1The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in ...
CVE-2024-11457MEDIUM6.1The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-11380MEDIUM6.4The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortco...
CVE-2024-12270HIGH7.5The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter ...
CVE-2024-12253MEDIUM5.4The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthoriz...
CVE-2024-12128MEDIUM6.1The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected ...
CVE-2024-11374MEDIUM6.1The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-11367MEDIUM6.1The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...
CVE-2024-11010HIGH7.2The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inclu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now