2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58106HIGH7.5Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail...
CVE-2024-58133MEDIUM4In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarti...
CVE-2024-58132MEDIUM4In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal...
CVE-2024-58131LOW3.7FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a ma...
CVE-2024-56370MEDIUM6.5Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograph...
CVE-2024-52322MEDIUM5.5WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt...
CVE-2024-58036MEDIUM5.5Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt...
CVE-2024-57868MEDIUM5.5Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographica...
CVE-2024-57835MEDIUM5.5Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values.  String::Random defaults to Perl's bui...
CVE-2024-13776HIGH8.1The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modificati...
CVE-2024-13604HIGH7.5The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to ...
CVE-2024-11235HIGH8.1In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and...
CVE-2024-51800CRITICAL9.8Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: f...
CVE-2024-42208LOW3.5HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in...
CVE-2024-13898MEDIUM4.4The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl...
CVE-2024-13708HIGH7.2The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ve...
CVE-2024-13645CRITICAL9.8The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,...
CVE-2024-13744CRITICAL9.8The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2024-56528HIGH7.5This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establish...
CVE-2024-47217MEDIUM6.5An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated ...
CVE-2024-47215HIGH7.5An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an in...
CVE-2024-47214HIGH7.5An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind ...
CVE-2024-47213HIGH7.5An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to th...
CVE-2024-47212HIGH7.5An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API end...
CVE-2024-45199HIGH8.8insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious param...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now