2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42995HIGH8.3VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migr...
CVE-2024-42994HIGH7.2VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection...
CVE-2024-42634CRITICAL9.8A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, ...
CVE-2024-6098MEDIUM5.9When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the...
CVE-2024-6004MEDIUM6.5A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a...
CVE-2024-5210MEDIUM6.5A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a...
CVE-2024-5209MEDIUM6.5A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a...
CVE-2024-4782MEDIUM6.5A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a...
CVE-2024-4781MEDIUM6.5A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a...
CVE-2024-4763HIGH7.8An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display...
CVE-2024-43810MEDIUM5.4In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
CVE-2024-43809MEDIUM6.1In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
CVE-2024-43808MEDIUM5.4In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
CVE-2024-43807MEDIUM5.4In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
CVE-2024-43381MEDIUM5.4reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Store...
CVE-2024-42486HIGH7.2Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x bra...
CVE-2024-2175HIGH7.8An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Di...
CVE-2024-7145HIGH8.8The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 ...
CVE-2024-7144MEDIUM5.4The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters...
CVE-2024-42466CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager a...
CVE-2024-42465CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager a...
CVE-2024-42464MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti...
CVE-2024-42463MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti...
CVE-2024-42462CRITICAL9.8Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This i...
CVE-2024-7147MEDIUM6.4The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now