2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48944MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a reques...
CVE-2024-9773HIGH8An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from...
CVE-2024-45361MEDIUM6.5A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation...
CVE-2024-45356HIGH7.3A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida...
CVE-2024-45355MEDIUM5.5A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida...
CVE-2024-45354MEDIUM4.3A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper inp...
CVE-2024-45353MEDIUM4.3An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is ca...
CVE-2024-45352HIGH8.8An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by impro...
CVE-2024-55965MEDIUM6.5An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development in...
CVE-2024-55964CRITICAL9.8An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea...
CVE-2024-55963MEDIUM6.5An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the ...
CVE-2024-41643MEDIUM6.8An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell log...
CVE-2024-45351HIGH7.8A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by imp...
CVE-2024-13889HIGH7.2The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ...
CVE-2024-13411MEDIUM6.4The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2024-13801HIGH8.1The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a ...
CVE-2024-13702MEDIUM5.4The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-30155MEDIUM4.3HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able t...
CVE-2024-13146HIGH8.8The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow att...
CVE-2024-12683LOW3.5The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ...
CVE-2024-11847MEDIUM4.8The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least ...
CVE-2024-47516CRITICAL9.8A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to re...
CVE-2024-55030CRITICAL9.8A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute ar...
CVE-2024-55029MEDIUM6.1NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2024-55028CRITICAL9.8A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now