2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10206MEDIUM6.9A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthentic...
CVE-2024-9103MEDIUM6.1Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messag...
CVE-2024-55279MEDIUM6Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.
CVE-2024-8774HIGH7.7The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to e...
CVE-2024-8773HIGH8.3SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt...
CVE-2024-13124LOW3.5The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which coul...
CVE-2024-10558LOW3.5The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ...
CVE-2024-13666MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2024-13856MEDIUM6.4The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Fo...
CVE-2024-13768MEDIUM4.3The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S...
CVE-2024-13739MEDIUM6.1The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versi...
CVE-2024-13737MEDIUM4.3The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-53351CRITICAL9.8Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalatio...
CVE-2024-53350HIGH7.4Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escal...
CVE-2024-53349HIGH7.4Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escal...
CVE-2024-53348HIGH7.4LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive informati...
CVE-2024-57490HIGH7.7Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system ...
CVE-2024-13903HIGH7.5A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulne...
CVE-2024-50053MEDIUM5.4Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below...
CVE-2024-54564MEDIUM6.5This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonom...
CVE-2024-54551HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, mac...
CVE-2024-44305HIGH7.8This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able t...
CVE-2024-44199HIGH7.1An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may...
CVE-2024-7598LOW3.1A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enf...
CVE-2024-57440HIGH7.5D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webpr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now