2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52976HIGH7.8Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attacker...
CVE-2024-11994MEDIUM5.7APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na...
CVE-2024-11390MEDIUM5.4Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro...
CVE-2024-13381MEDIUM4.8The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could...
CVE-2024-13845MEDIUM5.5The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ...
CVE-2024-30146LOW2.7Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server...
CVE-2024-30145MEDIUM6.1Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and ...
CVE-2024-30115MEDIUM5.4Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the...
CVE-2024-6032HIGH7.8Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attack...
CVE-2024-6031HIGH7.8Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local ...
CVE-2024-6030HIGH7Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to es...
CVE-2024-6029MEDIUM5Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attack...
CVE-2024-13943HIGH7.8Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil...
CVE-2024-9877MEDIUM5.3: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue af...
CVE-2024-9876HIGH8.5: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC...
CVE-2024-47784LOW2.6Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in th...
CVE-2024-57698HIGH7.5An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with...
CVE-2024-58099MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_...
CVE-2024-12273LOW3.5The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could...
CVE-2024-11922MEDIUM5.4Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an a...
CVE-2024-10635MEDIUM5.3Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthent...
CVE-2024-12706LOW2.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital ...
CVE-2024-32499CRITICAL9.8Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
CVE-2024-9771LOW3.5The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-13688MEDIUM5.3The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protectio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now