2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42208LOW3.5HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in...
CVE-2024-13898MEDIUM4.4The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl...
CVE-2024-13708HIGH7.2The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ve...
CVE-2024-13645CRITICAL9.8The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,...
CVE-2024-13744CRITICAL9.8The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2024-56528HIGH7.5This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establish...
CVE-2024-47217MEDIUM6.5An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated ...
CVE-2024-47215HIGH7.5An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an in...
CVE-2024-47214HIGH7.5An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind ...
CVE-2024-47213HIGH7.5An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to th...
CVE-2024-47212HIGH7.5An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API end...
CVE-2024-45199HIGH8.8insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious param...
CVE-2024-45198HIGH8.8insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters i...
CVE-2024-22611CRITICAL9.8OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.cl...
CVE-2024-4877HIGH8.8OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi...
CVE-2024-9416MEDIUM5.4The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc...
CVE-2024-53868HIGH7.5Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffi...
CVE-2024-13673MEDIUM6.4The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' s...
CVE-2024-38392CRITICAL9.1Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remo...
CVE-2024-37917HIGH7.5Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (so...
CVE-2024-36337HIGH7.9Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss ...
CVE-2024-36336HIGH7.9Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a...
CVE-2024-36328HIGH7.3Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss ...
CVE-2024-56476MEDIUM5.3IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login a...
CVE-2024-56475MEDIUM5.4IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authent...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now