2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13852HIGH8.8The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin...
CVE-2024-13684HIGH8.1The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. Th...
CVE-2024-13677HIGH8.8The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege e...
CVE-2024-13622HIGH7.5The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2024-12314HIGH7.2The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This ...
CVE-2024-13726HIGH8.6The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL st...
CVE-2024-13626HIGH7.1The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before ou...
CVE-2024-13625HIGH7.1The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-44044HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandexponents Osh...
CVE-2024-13488HIGH7.5The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' an...
CVE-2024-5462HIGH7.5If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP ...
CVE-2024-5461HIGH8Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch...
CVE-2024-8893HIGH7.3Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximi...
CVE-2024-57778HIGH8.8An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the serv...
CVE-2024-12651HIGH8.5Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variab...
CVE-2024-52500HIGH7.2Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly ...
CVE-2024-13641HIGH7.5The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature...
CVE-2024-2240HIGH7.2Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authe...
CVE-2024-55904HIGH7.2IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1....
CVE-2024-57378HIGH7.3Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creati...
CVE-2024-11347HIGH7.3Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter module...
CVE-2024-11346HIGH7.3: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. A...
CVE-2024-11345HIGH7.3A heap-based memory vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vuln...
CVE-2024-11344HIGH7.3A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnera...
CVE-2024-12013HIGH7.6A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now