2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13534HIGH7.5The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_i...
CVE-2024-13533HIGH7.5The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter ...
CVE-2024-13491HIGH7.5The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' ...
CVE-2024-13485HIGH7.5The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and '...
CVE-2024-13483HIGH7.5The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropshi...
CVE-2024-13481HIGH7.5The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and ...
CVE-2024-13479HIGH7.5The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and...
CVE-2024-13478HIGH7.5The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' a...
CVE-2024-13489HIGH7.5The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and ...
CVE-2024-13592HIGH8.8The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File In...
CVE-2024-13468HIGH7.5The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing ca...
CVE-2024-11582HIGH7.2The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-57262HIGH7.1In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via...
CVE-2024-57261HIGH7.1In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-5725...
CVE-2024-57258HIGH7.8Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk...
CVE-2024-56883HIGH8.1Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are no...
CVE-2024-51505HIGH8An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race con...
CVE-2024-50609HIGH7.5An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP addre...
CVE-2024-50608HIGH7.5An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on a...
CVE-2024-57046HIGH8.8A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individua...
CVE-2024-13681HIGH7.5The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_...
CVE-2024-13369HIGH8.8The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘re...
CVE-2024-57964HIGH7.3Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local a...
CVE-2024-57963HIGH7.3Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local at...
CVE-2024-13315HIGH8.8The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request For...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now