2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45351HIGH7.8A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by imp...
CVE-2024-13889HIGH7.2The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ...
CVE-2024-13411MEDIUM6.4The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2024-13801HIGH8.1The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a ...
CVE-2024-13702MEDIUM5.4The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-30155MEDIUM4.3HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able t...
CVE-2024-13146HIGH8.8The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow att...
CVE-2024-12683LOW3.5The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ...
CVE-2024-11847MEDIUM4.8The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least ...
CVE-2024-47516CRITICAL9.8A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to re...
CVE-2024-55030CRITICAL9.8A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute ar...
CVE-2024-55029MEDIUM6.1NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2024-55028CRITICAL9.8A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via...
CVE-2024-48818CRITICAL9.8An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.
CVE-2024-31896HIGH7.5IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow...
CVE-2024-58105HIGH7.8A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ...
CVE-2024-58104HIGH7.8A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ...
CVE-2024-55604MEDIUM4.3Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not h...
CVE-2024-42533CRITICAL9.8SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attacker...
CVE-2024-12169HIGH8.7A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allo...
CVE-2024-11499MEDIUM6.9A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and auth...
CVE-2024-10037MEDIUM5.9A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU applicati...
CVE-2024-53679MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the ...
CVE-2024-53678HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users ...
CVE-2024-13731MEDIUM6.4The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Sc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now