2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-34928HIGH7.3A SQL injection vulnerability in /model/update_subject_routing.php in Campcodes Complete Web-Based School Management Sys...
CVE-2024-2301HIGH7.6Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management...
CVE-2024-4471HIGH8The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object Injection in versions up t...
CVE-2024-34060HIGH8.8IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-ev...
CVE-2024-26139HIGH8.1OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observ...
CVE-2024-4779HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injecti...
CVE-2024-35186HIGH8.8gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to...
CVE-2024-30280HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when ...
CVE-2024-30279HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that...
CVE-2024-4835HIGH8.2A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By ...
CVE-2024-36013HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_...
CVE-2024-36012HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do...
CVE-2024-2038HIGH7.5The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthori...
CVE-2024-4388HIGH7.5This does not validate a path generated with user input when downloading files, allowing unauthenticated user to downlo...
CVE-2024-4347HIGH7.2The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2...
CVE-2024-3594HIGH8.7The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-4662HIGH8.8The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8...
CVE-2024-4978HIGH8.4Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected...
CVE-2024-29853HIGH7.8An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.
CVE-2024-29851HIGH7.2Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
CVE-2024-29850HIGH8.8Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
CVE-2024-4454HIGH7.8WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allo...
CVE-2024-4453HIGH7.8GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2024-27264HIGH7.8IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual...
CVE-2024-21791HIGH7.2Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin user...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now