2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45125MEDIUM4.3Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization v...
CVE-2024-45124MEDIUM5.3Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v...
CVE-2024-45123MEDIUM6.1Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scrip...
CVE-2024-45122MEDIUM4.3Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v...
CVE-2024-45121MEDIUM4.3Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v...
CVE-2024-45120LOW3.1Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use ...
CVE-2024-45119MEDIUM4.9Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forg...
CVE-2024-45118MEDIUM6.5Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v...
CVE-2024-45117HIGH7.6Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation...
CVE-2024-45116HIGH8.1Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS)...
CVE-2024-45115CRITICAL9.8Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication v...
CVE-2024-22068MEDIUM6.5Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 6...
CVE-2024-9802MEDIUM5.3The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The respons...
CVE-2024-9798MEDIUM5.3The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for at...
CVE-2024-9796CRITICAL9.8The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a...
CVE-2024-7049MEDIUM5.4In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending ...
CVE-2024-6747HIGH7.5Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to...
CVE-2024-9781HIGH7.5AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet i...
CVE-2024-9780MEDIUM5.5ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
CVE-2024-9156HIGH7.5The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping o...
CVE-2024-9520MEDIUM5.4The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ...
CVE-2024-9074MEDIUM5.4The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve...
CVE-2024-9067MEDIUM4.3The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-9022HIGH7.2The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘o...
CVE-2024-8477MEDIUM4.3The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now