2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41446MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scr...
CVE-2024-13926HIGH7.5The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain...
CVE-2024-53591CRITICAL9.8An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.
CVE-2024-57493MEDIUM5.5An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockop...
CVE-2024-41447MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scr...
CVE-2024-29643CRITICAL9.1An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
CVE-2024-11421——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: The developer has disputed this as a vulnerabili...
CVE-2024-46089MEDIUM6.374cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
CVE-2024-49808MEDIUM6.5IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity...
CVE-2024-45651MEDIUM6.5IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure w...
CVE-2024-26014——Rejected reason: Not used
CVE-2024-13650MEDIUM6.4The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before ...
CVE-2024-42178HIGH7.5HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori...
CVE-2024-42177MEDIUM6.4HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the...
CVE-2024-55211HIGH8.4An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.
CVE-2024-53924CRITICAL9.8Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell,...
CVE-2024-40124MEDIUM5.4Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.
CVE-2024-56518CRITICAL9.8Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelc...
CVE-2024-55238HIGH8.8OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2024-12530HIGH7Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.Thi...
CVE-2024-13925HIGH7.5The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint ...
CVE-2024-11924LOW3.5The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape som...
CVE-2024-55372CRITICAL9.8Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to ...
CVE-2024-55371CRITICAL9.8Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to res...
CVE-2024-53305HIGH7.3An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now