2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-5441HIGH8.8The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-6166HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ...
CVE-2024-39598HIGH7.7SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal...
CVE-2024-39597HIGH7.2In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B si...
CVE-2024-5974HIGH7.2A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management ...
CVE-2024-4944HIGH7.8A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user t...
CVE-2024-5793HIGH8.8The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter i...
CVE-2024-5549HIGH8.1A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs,...
CVE-2024-5971HIGH7.5A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers...
CVE-2024-6227HIGH7.5A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tr...
CVE-2024-6409HIGH7A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacke...
CVE-2024-39701HIGH7.7Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly...
CVE-2024-39202HIGH8.8D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd...
CVE-2024-31504HIGH7.5Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause ...
CVE-2024-23562HIGH7.5A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthen...
CVE-2024-21778HIGH7.2A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realte...
CVE-2024-25639HIGH7.5Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize...
CVE-2024-39743HIGH7.5IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service c...
CVE-2024-37999HIGH7.8A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes...
CVE-2024-27459HIGH7.8The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can ...
CVE-2024-24974HIGH7.5The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allo...
CVE-2024-38330HIGH7.8IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified...
CVE-2024-3651HIGH7.5A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting vers...
CVE-2024-40597HIGH7.5An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information fo...
CVE-2024-39486HIGH7In the Linux kernel, the following vulnerability has been resolved: drm/drm_file: Fix pid refcounting race <maarten.la...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now