2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6757MEDIUM4.3The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Ex...
CVE-2024-9548MEDIUM6.1The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in a...
CVE-2024-9546MEDIUM5.3The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to,...
CVE-2024-30117MEDIUM5.3A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file unde...
CVE-2024-9953MEDIUM4.9A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticate...
CVE-2024-35520MEDIUM6.8Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
CVE-2024-35519MEDIUM6.8Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in ...
CVE-2024-35518MEDIUM6.8Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
CVE-2024-6207HIGH7.5CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send ...
CVE-2024-48911HIGH7.8OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0...
CVE-2024-48909LOW2.4SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in versio...
CVE-2024-48824HIGH7.5An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attack...
CVE-2024-48823CRITICAL9.8Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r...
CVE-2024-48822HIGH8.8Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r...
CVE-2024-48821MEDIUM6.1Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799...
CVE-2024-47885MEDIUM5.4The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to ver...
CVE-2024-48795MEDIUM5.3An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive info...
CVE-2024-48793MEDIUM5.9An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware ...
CVE-2024-48792HIGH7.5An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update p...
CVE-2024-48791HIGH7.5An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive informati...
CVE-2024-48790MEDIUM5.3An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware ...
CVE-2024-48789HIGH7.5An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via th...
CVE-2024-47831HIGH7.5Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2....
CVE-2024-47826MEDIUM6.1eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows a...
CVE-2024-47767MEDIUM4.3Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now