2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10107MEDIUM4.8The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its sett...
CVE-2024-10098LOW2.7The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing ...
CVE-2024-10076MEDIUM5.9The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelera...
CVE-2024-10075MEDIUM5.6The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible t...
CVE-2024-10054MEDIUM4.8The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-10009MEDIUM4.1The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a S...
CVE-2024-0970MEDIUM5.3This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrust...
CVE-2024-0852HIGH8.8The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting i...
CVE-2024-0249HIGH7.1The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it...
CVE-2024-56006MEDIUM5.3Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a b...
CVE-2024-51666MEDIUM4.3Missing Authorization vulnerability in Tosin Oguntuyi Tours tours.This issue affects Tours: from n/a through <= 1.0.0.
CVE-2024-52880HIGH7.9An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-52879HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-52878HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-52877HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-13914HIGH7.2The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...
CVE-2024-45067HIGH8.2Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticat...
CVE-2024-56427MEDIUM6.5An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200,...
CVE-2024-55569HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2024-58101HIGH8.1Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to st...
CVE-2024-57096MEDIUM5.5An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.
CVE-2024-45516MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4...
CVE-2024-56157MEDIUM6.3iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV c...
CVE-2024-52601MEDIUM6.5iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account havi...
CVE-2024-10865CRITICAL9.4Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now