2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56474HIGH8.8IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker t...
CVE-2024-56341MEDIUM5.4IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an auth...
CVE-2024-25051HIGH7.2IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated p...
CVE-2024-50597HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50596HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50595HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50594HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50385HIGH7.5A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-50384HIGH7.5A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-45064CRITICAL9.8A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-13637MEDIUM6.5The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2024-12410MEDIUM4.9The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versi...
CVE-2024-39780CRITICAL9.8A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for g...
CVE-2024-45700MEDIUM6.5Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send special...
CVE-2024-45699MEDIUM5.4The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl param...
CVE-2024-42325LOW3.5Zabbix API user.get returns all users that share common group with the calling user. This includes media and other infor...
CVE-2024-36469LOW3.1Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.
CVE-2024-36465HIGH8.8A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer...
CVE-2024-13941MEDIUM5.3A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ou...
CVE-2024-13553CRITICAL9.8The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account t...
CVE-2024-56325CRITICAL9.8Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Norm...
CVE-2024-12278MEDIUM6.1The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typi...
CVE-2024-12189MEDIUM6.4The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres...
CVE-2024-13567HIGH7.5The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Ex...
CVE-2024-54533HIGH7A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now