2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13943HIGH7.8Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil...
CVE-2024-9877MEDIUM5.3: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue af...
CVE-2024-9876HIGH8.5: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC...
CVE-2024-47784LOW2.6Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in th...
CVE-2024-57698HIGH7.5An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with...
CVE-2024-58099MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_...
CVE-2024-12273LOW3.5The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could...
CVE-2024-11922MEDIUM5.4Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an a...
CVE-2024-10635MEDIUM5.3Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthent...
CVE-2024-12706LOW2.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital ...
CVE-2024-32499CRITICAL9.8Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
CVE-2024-9771LOW3.5The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-13688MEDIUM5.3The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protectio...
CVE-2024-52888MEDIUM5.4For an authenticated end-user the portal may run a script while attempting to display a directory or some file's propert...
CVE-2024-52887MEDIUM5.4Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing...
CVE-2024-53636CRITICAL9.8An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1....
CVE-2024-13812MEDIUM6.5The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
CVE-2024-13808HIGH8.8The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i...
CVE-2024-30152CRITICAL9.8HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain acce...
CVE-2024-56156CRITICAL9Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypa...
CVE-2024-57375LOW2.4Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c...
CVE-2024-6199HIGH7.7An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS ...
CVE-2024-6198HIGH7.7The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the ...
CVE-2024-11917HIGH8.1The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ...
CVE-2024-30127LOW3.2Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now