2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13885HIGH7.1The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-13884HIGH7.1The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-12380HIGH7.5An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f...
CVE-2024-26290HIGH8.7Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Av...
CVE-2024-13872HIGH7.5Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Int...
CVE-2024-13871HIGH8.8A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (fir...
CVE-2024-58087HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expir...
CVE-2024-9157HIGH7.8** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics...
CVE-2024-55597HIGH7.2A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 thr...
CVE-2024-55590HIGH8.8Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE...
CVE-2024-54026HIGH8.8An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 t...
CVE-2024-54018HIGH7.2Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox befo...
CVE-2024-52961HIGH8.8An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo...
CVE-2024-52960HIGH8.8A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 ...
CVE-2024-51321HIGH7.6In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to...
CVE-2024-51319HIGH7.3A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attac...
CVE-2024-45328HIGH7.8An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged admin...
CVE-2024-45324HIGH7.2A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2...
CVE-2024-54084HIGH7APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition ...
CVE-2024-56182HIGH8.2A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12...
CVE-2024-56181HIGH8.2A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07)...
CVE-2024-13864HIGH7.1The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-13862HIGH7.1The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise ...
CVE-2024-13836HIGH7.1The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13574HIGH7.1The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now