2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45641MEDIUM6.5IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate val...
CVE-2024-53359HIGH7.5An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.
CVE-2024-5878MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox Jav...
CVE-2024-33939MEDIUM5.3Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-...
CVE-2024-55063HIGH8.8Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execut...
CVE-2024-51106MEDIUM4.6A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation...
CVE-2024-4878——Rejected reason: Unused CVE record, incorrectly reserved
CVE-2024-13965——Rejected reason: wrong year
CVE-2024-13964——Rejected reason: wrong year
CVE-2024-13613HIGH7.5The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-47893MEDIUM6.5Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or w...
CVE-2024-40120MEDIUM6.5seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_sto...
CVE-2024-53827HIGH7.5Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra...
CVE-2024-8201MEDIUM5.4Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hi...
CVE-2024-51475MEDIUM6.1IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject maliciou...
CVE-2024-9882MEDIUM4.8The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does ...
CVE-2024-9879MEDIUM5.4The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a S...
CVE-2024-9838MEDIUM5.4The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL...
CVE-2024-9831HIGH7.2The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL stateme...
CVE-2024-9765MEDIUM6.5The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of th...
CVE-2024-9711MEDIUM5.4The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w...
CVE-2024-9709MEDIUM5.4The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w...
CVE-2024-9663MEDIUM5.4The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-9662MEDIUM5.4The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-9645MEDIUM5.4The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now