2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45790CRITICAL9.8This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authenticati...
CVE-2024-7609HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTE...
CVE-2024-5416MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-45789MEDIUM4.3This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API...
CVE-2024-45788HIGH7.5This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API e...
CVE-2024-45787MEDIUM6.5This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in...
CVE-2024-45786MEDIUM6.5This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints....
CVE-2024-8096MEDIUM6.5When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify tha...
CVE-2024-45327HIGH7.5An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 t...
CVE-2024-8277CRITICAL9.8The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,...
CVE-2024-8045MEDIUM5.4The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag’ ...
CVE-2024-7626HIGH8.1The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar...
CVE-2024-8440MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-7716MEDIUM4.8The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-3899MEDIUM4.8The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings...
CVE-2024-7727MEDIUM5.3The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of ...
CVE-2024-7721MEDIUM4.3The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modificati...
CVE-2024-43690HIGH8Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allo...
CVE-2024-21529HIGH8.8Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user ...
CVE-2024-1656LOW2.6Affected versions of Octopus Server had a weak content security policy.
CVE-2024-8253HIGH8.8The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to ...
CVE-2024-39808MEDIUM4.6Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows ...
CVE-2024-24972MEDIUM6.5Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface...
CVE-2024-23906MEDIUM6.1Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnost...
CVE-2024-40662HIGH7.8In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now