2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10294HIGH7.5The CE21 Suite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-10285HIGH7.5The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions...
CVE-2024-10284CRITICAL9.8The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This...
CVE-2024-52314MEDIUM6.9A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to ...
CVE-2024-52313MEDIUM5.3An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the pa...
CVE-2024-52312MEDIUM5.4Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to per...
CVE-2024-52311MEDIUM6.3Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticat...
CVE-2024-10953MEDIUM5.3An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.a...
CVE-2024-52009CRITICAL9.8Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs ...
CVE-2024-52007HIGH8.6HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing pe...
CVE-2024-52004HIGH8.7MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has b...
CVE-2024-52002HIGH8.8Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Reques...
CVE-2024-52001MEDIUM4.3Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access for...
CVE-2024-52000MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site ...
CVE-2024-35427MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser....
CVE-2024-35426CRITICAL9.8vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c.
CVE-2024-48073CRITICAL9.8sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is ...
CVE-2024-35425MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_funct...
CVE-2024-35424MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser....
CVE-2024-35423HIGH7.8vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_w...
CVE-2024-35422HIGH7.8vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.
CVE-2024-35421MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser...
CVE-2024-35420MEDIUM6.2wac commit 385e1 was discovered to contain a heap overflow.
CVE-2024-35419MEDIUM5.5wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerab...
CVE-2024-35418MEDIUM6.2wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerabi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now