2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13418HIGH8.8Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check ...
CVE-2024-13344HIGH7.5The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'pro...
CVE-2024-13322HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via...
CVE-2024-12023MEDIUM6.5The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 ...
CVE-2024-55913MEDIUM5.3IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacke...
CVE-2024-55912MEDIUM5.9IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker...
CVE-2024-55910MEDIUM6.5IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenti...
CVE-2024-55909MEDIUM6.5IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expan...
CVE-2024-52903HIGH7.5IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under...
CVE-2024-48907HIGH7.5Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.
CVE-2024-48906MEDIUM6.1Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.
CVE-2024-48905CRITICAL9.1Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
CVE-2024-52979HIGH7.5Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache ...
CVE-2024-52976HIGH7.8Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attacker...
CVE-2024-11994MEDIUM5.7APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na...
CVE-2024-11390MEDIUM5.4Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro...
CVE-2024-13381MEDIUM4.8The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could...
CVE-2024-13845MEDIUM5.5The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ...
CVE-2024-30146LOW2.7Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server...
CVE-2024-30145MEDIUM6.1Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and ...
CVE-2024-30115MEDIUM5.4Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the...
CVE-2024-6032HIGH7.8Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attack...
CVE-2024-6031HIGH7.8Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local ...
CVE-2024-6030HIGH7Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to es...
CVE-2024-6029MEDIUM5Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now