2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11398HIGH8.1Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality ...
CVE-2024-54664Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-52945. Reason: This candidate is a reservation d...
CVE-2024-54661CRITICAL9.8readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
CVE-2024-9404HIGH8.7This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of ...
CVE-2024-12123MEDIUM5.3A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authent...
CVE-2024-12099MEDIUM4.3The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in a...
CVE-2024-10885MEDIUM5.4The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's...
CVE-2024-11897MEDIUM5.4The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-11813MEDIUM6.1The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-11807MEDIUM6.1The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' paramet...
CVE-2024-11747MEDIUM6.4The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortc...
CVE-2024-11093MEDIUM5.5The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due ...
CVE-2024-10952HIGH7.3The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJ...
CVE-2024-10832MEDIUM6.1The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secre...
CVE-2024-10663MEDIUM4.3The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-10587HIGH8.8The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress...
CVE-2024-45207HIGH7DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the a...
CVE-2024-45206MEDIUM6.5A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests t...
CVE-2024-45205HIGH7.1An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Networ...
CVE-2024-45204MEDIUM4.3A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak N...
CVE-2024-42457MEDIUM6.5A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by le...
CVE-2024-42456HIGH8.8A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a me...
CVE-2024-42455HIGH8.1A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit i...
CVE-2024-42453HIGH8.1A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected...
CVE-2024-42452HIGH8.8A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now