2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41605HIGH8.4In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an updat...
CVE-2024-39319MEDIUM5.3aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024....
CVE-2024-9155MEDIUM4.3Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have no...
CVE-2024-30134HIGH7.5The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Un...
CVE-2024-9177MEDIUM5.4The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, them...
CVE-2024-46330HIGH7.4VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun ...
CVE-2024-46329HIGH8VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.
CVE-2024-46328HIGH8VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts,...
CVE-2024-46327MEDIUM5.7An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a dir...
CVE-2024-31899MEDIUM4.3IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user ...
CVE-2024-8633MEDIUM4.8The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ...
CVE-2024-7108CRITICAL9.8Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality ...
CVE-2024-7107HIGH7.5Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath all...
CVE-2024-8725MEDIUM5.4Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a...
CVE-2024-8704HIGH7.2The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a...
CVE-2024-8126HIGH8.8The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php'...
CVE-2024-9199HIGH7.5Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the ...
CVE-2024-9198MEDIUM5.4Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored X...
CVE-2024-9173MEDIUM5.4The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-9127MEDIUM5.4The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter i...
CVE-2024-9125MEDIUM5.4The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to...
CVE-2024-9117MEDIUM5.4The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ...
CVE-2024-9115MEDIUM5.4The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-9025MEDIUM5.3The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data d...
CVE-2024-8872MEDIUM6.1The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now