2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36541HIGH8.8Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obt...
CVE-2024-31970HIGH8.8AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default...
CVE-2024-22444MEDIUM6.1A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attack...
CVE-2024-7068MEDIUM4.6A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects...
CVE-2024-41914CRITICAL9A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2024-39345HIGH7.2AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented,...
CVE-2024-31977HIGH8.8Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via s...
CVE-2024-31971MEDIUM4.8Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote at...
CVE-2024-22443HIGH8.8A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2024-7067HIGH8.8A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It ...
CVE-2024-6327CRITICAL9.8In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible ...
CVE-2024-6096CRITICAL9.8In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object inject...
CVE-2024-5818MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via...
CVE-2024-3896MEDIUM5.4The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-7066CRITICAL9.8A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is ...
CVE-2024-6896MEDIUM5.4The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...
CVE-2024-7065MEDIUM4.3A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown funct...
CVE-2024-6930MEDIUM5.4The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute withi...
CVE-2024-6874MEDIUM4.3libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to...
CVE-2024-6197HIGH7.5libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid fi...
CVE-2024-3454LOW3.5An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK al...
CVE-2024-3297MEDIUM6.5An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between...
CVE-2024-39676HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pin...
CVE-2024-6629MEDIUM5.4The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video sh...
CVE-2024-6571MEDIUM5.3The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now