2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-56225HIGH8.8Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Accessing...
CVE-2024-56223HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Gulr...
CVE-2024-56210HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Userp...
CVE-2024-56209HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen Kleo ...
CVE-2024-12106HIGH7.5In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
CVE-2024-56232HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Alex Volkov WP Nice Loader wp-nice-loader allows Stored XSS.This issu...
CVE-2024-56230HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-56214HIGH8.3Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userp...
CVE-2024-56213HIGH8.8Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affect...
CVE-2024-56212HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DeluxeThemes Userp...
CVE-2024-56211HIGH8.8Missing Authorization vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1....
CVE-2024-45497HIGH7.6A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume m...
CVE-2024-13040HIGH8.8The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling ...
CVE-2024-12839HIGH8.8The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypas...
CVE-2024-12838HIGH8.8The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerabili...
CVE-2024-13051HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabili...
CVE-2024-13050HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabili...
CVE-2024-13049HIGH7.8Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2024-13048HIGH7.8Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-13047HIGH7.8Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2024-13046HIGH7.8Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-13045HIGH7.8Ashlar-Vellum Cobalt AR File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability...
CVE-2024-13044HIGH7.8Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-13043HIGH7.8Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers t...
CVE-2024-12753HIGH7.3Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to e...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now