2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7257CRITICAL9.8The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to mis...
CVE-2024-7031HIGH8.8The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2024-7291HIGH7.2The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3....
CVE-2024-6477HIGH7.5The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could all...
CVE-2024-6390MEDIUM5.9The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz ...
CVE-2024-7319MEDIUM5An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through...
CVE-2024-3056HIGH7.7A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur...
CVE-2024-38891HIGH7.5An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38887CRITICAL9.8An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-42349MEDIUM5.3FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorize...
CVE-2024-42348HIGH8.6FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and passw...
CVE-2024-38889CRITICAL9.8An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38888MEDIUM6.8An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-28298HIGH8.8SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands v...
CVE-2024-28297HIGH7.5SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via ...
CVE-2024-22169HIGH7.1WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow c...
CVE-2024-38886CRITICAL9.8An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38885HIGH7.5An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38884HIGH7.8An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38883CRITICAL9.1An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38882CRITICAL9.8An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-38881HIGH7.5An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows...
CVE-2024-33896HIGH7.2Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due...
CVE-2024-33895MEDIUM6.6Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the conf...
CVE-2024-33894HIGH8.8Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now