2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48818CRITICAL9.8An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.
CVE-2024-31896HIGH7.5IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow...
CVE-2024-58105HIGH7.8A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ...
CVE-2024-58104HIGH7.8A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ...
CVE-2024-55604MEDIUM4.3Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not h...
CVE-2024-42533CRITICAL9.8SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attacker...
CVE-2024-12169HIGH8.7A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allo...
CVE-2024-11499MEDIUM6.9A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and auth...
CVE-2024-10037MEDIUM5.9A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU applicati...
CVE-2024-53679MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the ...
CVE-2024-53678HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users ...
CVE-2024-13731MEDIUM6.4The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-13710MEDIUM4.3The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2024-13690HIGH7.2The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi...
CVE-2024-12623MEDIUM6.4The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in ...
CVE-2024-9770MEDIUM4.7The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statem...
CVE-2024-44903HIGH7.5SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is ava...
CVE-2024-13863HIGH7.1The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputt...
CVE-2024-13618HIGH7.2The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download....
CVE-2024-13617HIGH8.6The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unau...
CVE-2024-13123LOW3.5The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2024-13122LOW3.5The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2024-13118MEDIUM4.3The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-12769LOW3.5The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi...
CVE-2024-12682MEDIUM6.1The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now