2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58136CRITICAL9.8Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres...
CVE-2024-55210CRITICAL9.8An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via ...
CVE-2024-8243MEDIUM6.3The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and i...
CVE-2024-6860MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix setting...
CVE-2024-6857MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body ...
CVE-2024-55354HIGH8.8Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a prot...
CVE-2024-12556CRITICAL9.8Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
CVE-2024-52981HIGH7.5An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested ...
CVE-2024-52980MEDIUM6.5A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the ...
CVE-2024-52974MEDIUM6.5An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana serve...
CVE-2024-48887CRITICAL9.8A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c...
CVE-2024-54025MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-54024HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-52962MEDIUM5.3An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4...
CVE-2024-50565HIGH7.5A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio...
CVE-2024-46671HIGH7.2An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, versi...
CVE-2024-32122MEDIUM4.4A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7...
CVE-2024-26013HIGH7.5A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio...
CVE-2024-54092CRITICAL9.8A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device K...
CVE-2024-41796MEDIUM6.9A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41795MEDIUM6.9A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41794CRITICAL9.8A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcod...
CVE-2024-41793HIGH7.5A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41792HIGH7.5A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41791MEDIUM6.5A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now