2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6310HIGH8.8The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload ...
CVE-2024-6309HIGH8.8The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File ...
CVE-2024-6180HIGH7.2The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-6161HIGH8.8The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-6123HIGH7.2The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic...
CVE-2024-28750HIGH7.2A remote attacker with high privileges may use a deleting file function to inject OS commands.
CVE-2024-28749HIGH7.2A remote attacker with high privileges may use a writing file function to inject OS commands.
CVE-2024-28748HIGH7.2A remote attacker with high privileges may use a reading file function to inject OS commands.
CVE-2024-22062HIGH8.8There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis...
CVE-2024-5441HIGH8.8The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-6166HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ...
CVE-2024-39598HIGH7.7SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal...
CVE-2024-39597HIGH7.2In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B si...
CVE-2024-5974HIGH7.2A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management ...
CVE-2024-4944HIGH7.8A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user t...
CVE-2024-5793HIGH8.8The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter i...
CVE-2024-5549HIGH8.1A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs,...
CVE-2024-5971HIGH7.5A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers...
CVE-2024-6227HIGH7.5A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tr...
CVE-2024-6409HIGH7A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacke...
CVE-2024-39701HIGH7.7Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly...
CVE-2024-39202HIGH8.8D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd...
CVE-2024-31504HIGH7.5Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause ...
CVE-2024-23562HIGH7.5A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthen...
CVE-2024-21778HIGH7.2A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realte...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now