2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10260MEDIUM6.1The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, a...
CVE-2024-10113MEDIUM5.4The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-9609MEDIUM6.1The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-...
CVE-2024-10897MEDIUM4.3The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing c...
CVE-2024-10924CRITICAL9.8The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass ...
CVE-2024-11120CRITICAL9.8Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit t...
CVE-2024-52613MEDIUM5.5A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Servic...
CVE-2024-52308CRITICAL9.6The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH serve...
CVE-2024-49778HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service ...
CVE-2024-49777HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ...
CVE-2024-49776MEDIUM6.5A negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) v...
CVE-2024-41217MEDIUM6.5A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service ...
CVE-2024-41209HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ...
CVE-2024-41206MEDIUM6.5A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disc...
CVE-2024-51679MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue aff...
CVE-2024-51659HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XS...
CVE-2024-51658HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.Thi...
CVE-2024-51156MEDIUM4.707FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/...
CVE-2024-50968HIGH7.5A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1....
CVE-2024-48974CRITICAL9.3The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for ...
CVE-2024-48973CRITICAL9.3The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and rece...
CVE-2024-48971CRITICAL9.3The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This c...
CVE-2024-48970CRITICAL9.3The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and r...
CVE-2024-48967CRITICAL10The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activit...
CVE-2024-48966CRITICAL10The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now