2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7272HIGH8.8A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audio...
CVE-2024-7006HIGH7.5A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger me...
CVE-2024-6760HIGH7.5A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it sh...
CVE-2024-6759MEDIUM5.3When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separa...
CVE-2024-6758MEDIUM6.5Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low pri...
CVE-2024-6692LOW3.1The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr...
CVE-2024-6691MEDIUM4The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr...
CVE-2024-6684CRITICAL9.9Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Au...
CVE-2024-6640MEDIUM6.3In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Reques...
CVE-2024-6562MEDIUM5.3The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all ver...
CVE-2024-6158MEDIUM4.8The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4...
CVE-2024-6136MEDIUM5.4The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could all...
CVE-2024-6134MEDIUM5.4The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputtin...
CVE-2024-6133MEDIUM6.5The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputtin...
CVE-2024-5801MEDIUM5.3Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise ...
CVE-2024-5800HIGH7.5Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before...
CVE-2024-5651HIGH8.8A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) pr...
CVE-2024-5527HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing co...
CVE-2024-5487HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface a...
CVE-2024-5445LOW3.8Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS cert...
CVE-2024-4360MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-4359MEDIUM6.5The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-4350MEDIUM4.8Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is s...
CVE-2024-43168MEDIUM4.8DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, ...
CVE-2024-43167LOW2.8DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now