2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13338MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2024-13337MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2024-11679MEDIUM6.7An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could all...
CVE-2024-13861HIGH7.8A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3....
CVE-2024-52280HIGH7.7A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch ...
CVE-2024-52282MEDIUM6.2A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET ...
CVE-2024-51461MEDIUM6.5IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupt...
CVE-2024-11129HIGH7.5An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10...
CVE-2024-38865HIGH8.8Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0...
CVE-2024-13909MEDIUM4.9The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderb...
CVE-2024-13896MEDIUM6.5The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-...
CVE-2024-13874HIGH7.1The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-10894MEDIUM6.4The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc...
CVE-2024-58136CRITICAL9.8Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres...
CVE-2024-55210CRITICAL9.8An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via ...
CVE-2024-8243MEDIUM6.3The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and i...
CVE-2024-6860MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix setting...
CVE-2024-6857MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body ...
CVE-2024-55354HIGH8.8Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a prot...
CVE-2024-12556CRITICAL9.8Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
CVE-2024-52981HIGH7.5An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested ...
CVE-2024-52980MEDIUM6.5A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the ...
CVE-2024-52974MEDIUM6.5An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana serve...
CVE-2024-48887CRITICAL9.8A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c...
CVE-2024-54025MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now