2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42177MEDIUM6.4HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the...
CVE-2024-55211HIGH8.4An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.
CVE-2024-53924CRITICAL9.8Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell,...
CVE-2024-40124MEDIUM5.4Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.
CVE-2024-56518CRITICAL9.8Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelc...
CVE-2024-55238HIGH8.8OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2024-12530HIGH7Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.Thi...
CVE-2024-13925HIGH7.5The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint ...
CVE-2024-11924LOW3.5The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape som...
CVE-2024-55372CRITICAL9.8Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to ...
CVE-2024-55371CRITICAL9.8Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to res...
CVE-2024-53305HIGH7.3An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supp...
CVE-2024-53304MEDIUM6.5An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and ...
CVE-2024-53303HIGH8.8A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al...
CVE-2024-40074MEDIUM4.8Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat...
CVE-2024-40073CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template p...
CVE-2024-40072CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2024-40071CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge...
CVE-2024-40070MEDIUM5.1Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge...
CVE-2024-40069MEDIUM5.4Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat...
CVE-2024-40068MEDIUM5.9Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2024-22314HIGH7.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c...
CVE-2024-58249LOW3.7In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL.
CVE-2024-56736MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating):...
CVE-2024-58097MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor d...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now