2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-5348HIGH8.8The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi...
CVE-2024-3821HIGH7.3The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unau...
CVE-2024-4958HIGH7.1The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ...
CVE-2024-3564HIGH8.8The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2024-5138HIGH8.1The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged a...
CVE-2024-34009HIGH7.5Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not ...
CVE-2024-34008HIGH8.8Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
CVE-2024-34007HIGH8.8The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged o...
CVE-2024-36844HIGH7.5libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows atta...
CVE-2024-36843HIGH7.5libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
CVE-2024-34001HIGH8.4Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
CVE-2024-5564HIGH8.1A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManage...
CVE-2024-23316HIGH8.8HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to s...
CVE-2024-29848HIGH7.2An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, pri...
CVE-2024-29846HIGH8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac...
CVE-2024-29830HIGH8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac...
CVE-2024-29829HIGH8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac...
CVE-2024-29828HIGH8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac...
CVE-2024-29827HIGH8.8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att...
CVE-2024-29826HIGH8.8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att...
CVE-2024-29825HIGH8.8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att...
CVE-2024-29824HIGH8.8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att...
CVE-2024-29823HIGH8.8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att...
CVE-2024-29822HIGH8.8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att...
CVE-2024-22059HIGH8.8A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/mod...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now