2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39780CRITICAL9.8A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for g...
CVE-2024-45700MEDIUM6.5Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send special...
CVE-2024-45699MEDIUM5.4The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl param...
CVE-2024-42325LOW3.5Zabbix API user.get returns all users that share common group with the calling user. This includes media and other infor...
CVE-2024-36469LOW3.1Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.
CVE-2024-36465HIGH8.8A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer...
CVE-2024-13941MEDIUM5.3A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ou...
CVE-2024-13553CRITICAL9.8The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account t...
CVE-2024-56325CRITICAL9.8Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Norm...
CVE-2024-12278MEDIUM6.1The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typi...
CVE-2024-12189MEDIUM6.4The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres...
CVE-2024-13567HIGH7.5The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Ex...
CVE-2024-54533HIGH7A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS...
CVE-2024-40864LOW2.7The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequ...
CVE-2024-54809CRITICAL9.8Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header fu...
CVE-2024-54808CRITICAL9.8Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionSe...
CVE-2024-54807CRITICAL9.8In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exe...
CVE-2024-54806CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execu...
CVE-2024-54805CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54804CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54803CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54802CRITICAL9.8In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow...
CVE-2024-24456MEDIUM5.9An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentia...
CVE-2024-12021HIGH8.5Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interf...
CVE-2024-55093MEDIUM4.7phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now