2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8199MEDIUM4.3The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for Wor...
CVE-2024-45264HIGH8.8A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote...
CVE-2024-44342CRITICAL9.8D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_s...
CVE-2024-44341CRITICAL9.8D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcp...
CVE-2024-44340HIGH8.8D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_e...
CVE-2024-41622CRITICAL9.8D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_...
CVE-2024-40395MEDIUM6.5An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, inclu...
CVE-2024-6633CRITICAL9.8The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowled...
CVE-2024-6632HIGH7.2A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an ...
CVE-2024-7071CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hiberna...
CVE-2024-8182HIGH7.5An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of ...
CVE-2024-8181HIGH8.1An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attac...
CVE-2024-7941MEDIUM4.3An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified U...
CVE-2024-7940CRITICAL9.8The product exposes a service that is intended for local only to all network interfaces without any authentication.
CVE-2024-4872HIGH8.8A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an ...
CVE-2024-3982HIGH8.2An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging suppor...
CVE-2024-3980HIGH8.8The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that ...
CVE-2024-8207MEDIUM6.7In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating S...
CVE-2024-8197Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-7859. Reason: This candidate is a r...
CVE-2024-7791MEDIUM5.4The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-6789MEDIUM6.5A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 2...
CVE-2024-8046MEDIUM6.4The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-7608MEDIUM5.9An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.
CVE-2024-41176HIGH7.3The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Ser...
CVE-2024-41175MEDIUM5.5The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privilege...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now