2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10497HIGH8.8CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker t...
CVE-2024-13377HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versi...
CVE-2024-12476HIGH8.4CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclos...
CVE-2024-12399HIGH7.1CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t...
CVE-2024-11425HIGH8.7CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product whe...
CVE-2024-13333HIGH7.5The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2024-52363HIGH7.5IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker ...
CVE-2024-34579HIGH8.5Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbi...
CVE-2024-57704HIGH8.8Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi...
CVE-2024-55511HIGH7.8A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system ...
CVE-2024-54660HIGH8.7A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala be...
CVE-2024-46450HIGH8.1Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attacke...
CVE-2024-57578HIGH8.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm functio...
CVE-2024-55954HIGH8.7OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/use...
CVE-2024-52791HIGH7.5Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to oth...
CVE-2024-36403HIGH7.5Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 ...
CVE-2024-57775HIGH8.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?ins...
CVE-2024-57770HIGH8.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContr...
CVE-2024-57769HIGH8.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listDa...
CVE-2024-50633HIGH7.5A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by...
CVE-2024-57162HIGH7.2Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.
CVE-2024-12613HIGH7.5The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fu...
CVE-2024-45331HIGH7.8A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 throug...
CVE-2024-57728HIGH7.2SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file s...
CVE-2024-57727HIGH7.5SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now