2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13804CRITICAL9.8Unauthenticated RCE in HPE Insight Cluster Management Utility
CVE-2024-55895MEDIUM5.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2024-11180MEDIUM5.4The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Tim...
CVE-2024-13557MEDIUM6.5The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t...
CVE-2024-7577HIGH7.5IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation ...
CVE-2024-51477MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an...
CVE-2024-43186MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored ...
CVE-2024-58130MEDIUM6.1In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization...
CVE-2024-58129MEDIUM4.8In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and t...
CVE-2024-58128MEDIUM4.8In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus a...
CVE-2024-23338——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-53427. Reason: This candidate is a ...
CVE-2024-6875MEDIUM6.5A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak ...
CVE-2024-57083HIGH7.5A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attac...
CVE-2024-56975CRITICAL9.8InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerabilit...
CVE-2024-38988CRITICAL9.8alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/inde...
CVE-2024-38985CRITICAL9.8janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() met...
CVE-2024-24292CRITICAL9.8A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function...
CVE-2024-54362HIGH8.1Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This is...
CVE-2024-54291HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass plugin...
CVE-2024-51624HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-...
CVE-2024-48615HIGH7.5Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pa...
CVE-2024-39311MEDIUM5.4Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions...
CVE-2024-7407HIGH8.2Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords ...
CVE-2024-11504HIGH8.6Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, w...
CVE-2024-12619MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now