2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-2658HIGH8.5A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configur...
CVE-2024-13707HIGH8.1The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-13671HIGH7.5The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4...
CVE-2024-13646HIGH8.1The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial o...
CVE-2024-12269HIGH7.5The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2024-12129HIGH8.8The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escala...
CVE-2024-11600HIGH7.2The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t...
CVE-2024-10591HIGH8.8The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for Word...
CVE-2024-13453HIGH7.3The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcod...
CVE-2024-13694HIGH7.5The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is...
CVE-2024-12708HIGH7.1The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outpu...
CVE-2024-12638HIGH7.1The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-12400HIGH7.1The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leadin...
CVE-2024-57510HIGH7.8Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex...
CVE-2024-57509HIGH7.8Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex...
CVE-2024-54851HIGH8.8Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.
CVE-2024-48761HIGH8.8Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScr...
CVE-2024-23733HIGH7.5The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core...
CVE-2024-12705HIGH7.5Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or i...
CVE-2024-11187HIGH7.5It is possible to construct a zone such that some queries to it will generate responses containing numerous records in t...
CVE-2024-10001HIGH7.1A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious cod...
CVE-2024-57436HIGH7.2RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring...
CVE-2024-54462HIGH7.1The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu...
CVE-2024-54461HIGH7.1The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious doc...
CVE-2024-7695HIGH8.7Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient inp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now