2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46546HIGH7.3NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formF...
CVE-2024-40446CRITICAL9.8An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script
CVE-2024-40445HIGH7.3A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read ...
CVE-2024-11299HIGH7.5The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2024-13569HIGH7.1The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-46899HIGH7.1Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia...
CVE-2024-58250CRITICAL9.3The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
CVE-2024-57394HIGH8.8The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore ...
CVE-2024-12543MEDIUM5.9User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows...
CVE-2024-42699MEDIUM6.5Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to i...
CVE-2024-12863MEDIUM5.6Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malic...
CVE-2024-12862MEDIUM5.5Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the...
CVE-2024-41446MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scr...
CVE-2024-13926HIGH7.5The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain...
CVE-2024-53591CRITICAL9.8An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.
CVE-2024-57493MEDIUM5.5An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockop...
CVE-2024-41447MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scr...
CVE-2024-29643CRITICAL9.1An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
CVE-2024-11421Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: The developer has disputed this as a vulnerabili...
CVE-2024-46089MEDIUM6.374cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
CVE-2024-49808MEDIUM6.5IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity...
CVE-2024-45651MEDIUM6.5IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure w...
CVE-2024-26014Rejected reason: Not used
CVE-2024-13650MEDIUM6.4The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before ...
CVE-2024-42178HIGH7.5HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now