2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-12284HIGH8.8Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
CVE-2024-5706HIGH8.8The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input befor...
CVE-2024-5705HIGH8.8The product performs an authorization check when an actor attempts to access a resource or perform an action, but it doe...
CVE-2024-37359HIGH8.6The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but ...
CVE-2024-52541HIGH8.2Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access cou...
CVE-2024-45084HIGH8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to con...
CVE-2024-28777HIGH8.8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserializat...
CVE-2024-52902HIGH8.8IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded databas...
CVE-2024-13534HIGH7.5The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_i...
CVE-2024-13533HIGH7.5The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter ...
CVE-2024-13491HIGH7.5The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' ...
CVE-2024-13485HIGH7.5The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and '...
CVE-2024-13483HIGH7.5The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropshi...
CVE-2024-13481HIGH7.5The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and ...
CVE-2024-13479HIGH7.5The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and...
CVE-2024-13478HIGH7.5The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' a...
CVE-2024-13489HIGH7.5The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and ...
CVE-2024-13592HIGH8.8The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File In...
CVE-2024-13468HIGH7.5The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing ca...
CVE-2024-11582HIGH7.2The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-57262HIGH7.1In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via...
CVE-2024-57261HIGH7.1In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-5725...
CVE-2024-57258HIGH7.8Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk...
CVE-2024-56883HIGH8.1Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are no...
CVE-2024-51505HIGH8An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race con...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now