2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9017MEDIUM6.4The PeepSo Core: Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Group Description fiel...
CVE-2024-35164HIGH7.5The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers...
CVE-2024-13786CRITICAL9.8The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via...
CVE-2024-13451HIGH7.5The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-11405MEDIUM6.1The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email a...
CVE-2024-49365HIGH8.1tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can...
CVE-2024-49364HIGH8.1tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing ...
CVE-2024-46993MEDIUM4.4Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In ...
CVE-2024-46992HIGH7.8Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Fro...
CVE-2024-12915MEDIUM4.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Sof...
CVE-2024-53621HIGH7.5A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allow...
CVE-2024-8419HIGH7.5The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the ...
CVE-2024-24915HIGH7.2Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump ...
CVE-2024-52900MEDIUM5.4IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scrip...
CVE-2024-39730MEDIUM5.4IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim....
CVE-2024-36347MEDIUM6.4Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri...
CVE-2024-12364CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Softwar...
CVE-2024-12150CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Woww...
CVE-2024-12143CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile In...
CVE-2024-11739CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics C...
CVE-2024-12827CRITICAL9.8The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take...
CVE-2024-52928HIGH8.3Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permi...
CVE-2024-56915MEDIUM6.5Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.
CVE-2024-6174HIGH8.8When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To preven...
CVE-2024-11584MEDIUM5.3cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grant...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now