2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46935HIGH7.5Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers...
CVE-2024-46934MEDIUM6.1Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XS...
CVE-2024-46612CRITICAL9.8IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication...
CVE-2024-46610HIGH7.5An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including...
CVE-2024-46609HIGH7.5An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticat...
CVE-2024-46607HIGH7.6Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values a...
CVE-2024-45599LOW3.8Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access ...
CVE-2024-45373HIGH8.8Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.
CVE-2024-45066CRITICAL9.8A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject a...
CVE-2024-43693CRITICAL9.8A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inj...
CVE-2024-43692CRITICAL9.8An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting t...
CVE-2024-43423CRITICAL9.8The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that...
CVE-2024-42797CRITICAL9.8An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Managem...
CVE-2024-42507CRITICAL9.8Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s...
CVE-2024-42506CRITICAL9.8Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s...
CVE-2024-42505CRITICAL9.8Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s...
CVE-2024-41725MEDIUM6.1ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may ...
CVE-2024-39928HIGH7.5In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the To...
CVE-2024-38324MEDIUM6.5IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registrati...
CVE-2024-21545HIGH8.2Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient saf...
CVE-2024-8794MEDIUM5.3The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and includi...
CVE-2024-8791CRITICAL9.8The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnera...
CVE-2024-8671CRITICAL9.1The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insuffi...
CVE-2024-8628MEDIUM5.4The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable ...
CVE-2024-8624CRITICAL9.9The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attrib...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now