2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53967MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-42176HIGH8HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous ...
CVE-2024-55551HIGH8.3An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into...
CVE-2024-45644MEDIUM4.7IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatical...
CVE-2024-13933HIGH8.8The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request F...
CVE-2024-13442CRITICAL9.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2024-12920HIGH8.8The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access ...
CVE-2024-13790CRITICAL9.8The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion ...
CVE-2024-12137HIGH7.6Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. T...
CVE-2024-12136HIGH7.8Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass...
CVE-2024-13412HIGH7.5The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-13410CRITICAL9.8The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ...
CVE-2024-50631HIGH7.5Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing...
CVE-2024-50630HIGH7.5Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4...
CVE-2024-50629MEDIUM5.3Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1...
CVE-2024-12922CRITICAL9.8The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation ...
CVE-2024-12295HIGH8.8The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers...
CVE-2024-11131CRITICAL9.8A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute ar...
CVE-2024-10442CRITICAL10Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0...
CVE-2024-10445MEDIUM5.3Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-653...
CVE-2024-10444HIGH7.5Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-4...
CVE-2024-10441CRITICAL9.8Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before...
CVE-2024-57151MEDIUM6.8SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via...
CVE-2024-12563HIGH8.8The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214...
CVE-2024-56347CRITICAL9.6IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary comma...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now