2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-30458HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects W...
CVE-2024-30457HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issu...
CVE-2024-30456HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.
CVE-2024-2848HIGH7.5The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-3061HIGH7.2The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a...
CVE-2024-1872HIGH8.8The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via d...
CVE-2024-0913HIGH7.2The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-28960HIGH8.2An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA C...
CVE-2024-28714HIGH8.1SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the...
CVE-2024-23727HIGH8.4The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker ...
CVE-2024-3019HIGH8.8A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowi...
CVE-2024-2947HIGH7.3A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a comman...
CVE-2024-25963HIGH7.5Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability...
CVE-2024-25960HIGH7.8Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulner...
CVE-2024-25955HIGH8.8Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could pot...
CVE-2024-25954HIGH7.5Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A rem...
CVE-2024-25946HIGH8.8Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could pot...
CVE-2024-31139HIGH8.1In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
CVE-2024-31136HIGH7.4In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
CVE-2024-30612HIGH8.1Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from for...
CVE-2024-30604HIGH7.5Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.
CVE-2024-30601HIGH8Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.
CVE-2024-30600HIGH8Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.
CVE-2024-30599HIGH8.8Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.
CVE-2024-0259HIGH7.3Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now