2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10210HIGH8.4An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an ...
CVE-2024-10105MEDIUM5.9The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-8315MEDIUM6.8An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may ...
CVE-2024-8314MEDIUM5.5An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in ...
CVE-2024-8313HIGH8.7An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an I...
CVE-2024-45484HIGH7.2An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used...
CVE-2024-45483HIGH7A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow ...
CVE-2024-45482HIGH8.5An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may a...
CVE-2024-45481HIGH8.5An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may all...
CVE-2024-45480CRITICAL9.2An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APR...
CVE-2024-10209HIGH8.5An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may ...
CVE-2024-10208MEDIUM5.1An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <...
CVE-2024-10207MEDIUM5.3A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticat...
CVE-2024-10206MEDIUM6.9A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthentic...
CVE-2024-9103MEDIUM6.1Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messag...
CVE-2024-55279MEDIUM6Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.
CVE-2024-8774HIGH7.7The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to e...
CVE-2024-8773HIGH8.3SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt...
CVE-2024-13124LOW3.5The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which coul...
CVE-2024-10558LOW3.5The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ...
CVE-2024-13666MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2024-13856MEDIUM6.4The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Fo...
CVE-2024-13768MEDIUM4.3The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S...
CVE-2024-13739MEDIUM6.1The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versi...
CVE-2024-13737MEDIUM4.3The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data d...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now