2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58134HIGH8.1Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC sessio...
CVE-2024-41753MEDIUM6.1IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross...
CVE-2024-58135MEDIUM5.3Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate a...
CVE-2024-13738HIGH7.3The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-55069MEDIUM5.3ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.
CVE-2024-58253LOW2.9In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to inva...
CVE-2024-11142HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forge...
CVE-2024-13860MEDIUM5.4The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ param...
CVE-2024-13859MEDIUM5.4The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_...
CVE-2024-13858MEDIUM5.4The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘in...
CVE-2024-13420MEDIUM4.3Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on ...
CVE-2024-13419MEDIUM5.4Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to ...
CVE-2024-13418HIGH8.8Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check ...
CVE-2024-13344HIGH7.5The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'pro...
CVE-2024-13322HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via...
CVE-2024-12023MEDIUM6.5The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 ...
CVE-2024-55913MEDIUM5.3IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacke...
CVE-2024-55912MEDIUM5.9IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker...
CVE-2024-55910MEDIUM6.5IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenti...
CVE-2024-55909MEDIUM6.5IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expan...
CVE-2024-52903HIGH7.5IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under...
CVE-2024-48907HIGH7.5Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.
CVE-2024-48906MEDIUM6.1Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.
CVE-2024-48905CRITICAL9.1Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
CVE-2024-52979HIGH7.5Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now