2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37068HIGH7.5IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms t...
CVE-2024-7620MEDIUM6.6The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2024-7112MEDIUM6.5The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘s...
CVE-2024-6010MEDIUM5.3The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and incl...
CVE-2024-1596MEDIUM6.1The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e...
CVE-2024-8538MEDIUM4.3The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in a...
CVE-2024-8523HIGH7.2A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatD...
CVE-2024-6849MEDIUM5.4The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-8521MEDIUM6.1A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index o...
CVE-2024-45498HIGH8.8Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an ...
CVE-2024-45034HIGH8.8Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG fold...
CVE-2024-8439Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdra...
CVE-2024-45771CRITICAL9.8RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin...
CVE-2024-44839CRITICAL9.8RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article....
CVE-2024-44838CRITICAL9.8RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin...
CVE-2024-44845HIGH8.8DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value para...
CVE-2024-44844HIGH8.8DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name param...
CVE-2024-34158HIGH7.5Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
CVE-2024-34156HIGH7.5Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. T...
CVE-2024-34155MEDIUM4.3Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stac...
CVE-2024-7652HIGH7.5An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially...
CVE-2024-8394MEDIUM6.5When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a p...
CVE-2024-45295Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-45294. Reason: This candidate is a ...
CVE-2024-38642HIGH7.8An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability co...
CVE-2024-38641HIGH7.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now