2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13343HIGH8.8The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability...
CVE-2024-12171HIGH8.8The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due t...
CVE-2024-57434HIGH8.8macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test...
CVE-2024-57433HIGH7.5macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, the...
CVE-2024-53357HIGH7.5Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated at...
CVE-2024-53355HIGH8.8Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated ...
CVE-2024-57432HIGH7.5macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do no...
CVE-2024-53582HIGH7.5An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec...
CVE-2024-53319HIGH7.5A heap buffer overflow in the XML Text Escaping component of Qualisys C++ SDK commit a32a21a allows attackers to cause D...
CVE-2024-45650HIGH7.5IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended ope...
CVE-2024-13472HIGH7.3The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio...
CVE-2024-52875HIGH8.8An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE...
CVE-2024-13504HIGH7.2The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-47900HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.
CVE-2024-47899HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-47898HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-47891HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-46974HIGH7.8Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA ...
CVE-2024-13767HIGH8.1The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati...
CVE-2024-23929HIGH7.3This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-...
CVE-2024-23921HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint ...
CVE-2024-23920HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint ...
CVE-2024-24731HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs...
CVE-2024-23973HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs...
CVE-2024-23971HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now