2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13878HIGH7.1The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13877HIGH7.1The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before ou...
CVE-2024-13876HIGH7.1The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13875HIGH7.1The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-55009MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and...
CVE-2024-7631MEDIUM4.3A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/re...
CVE-2024-57061CRITICAL9.8An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via ...
CVE-2024-51459HIGH7.8IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handl...
CVE-2024-25132MEDIUM4.3A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshi...
CVE-2024-53970MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-53969MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-53968MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-53967MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-42176HIGH8HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous ...
CVE-2024-55551HIGH8.3An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into...
CVE-2024-45644MEDIUM4.7IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatical...
CVE-2024-13933HIGH8.8The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request F...
CVE-2024-13442CRITICAL9.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2024-12920HIGH8.8The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access ...
CVE-2024-13790CRITICAL9.8The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion ...
CVE-2024-12137HIGH7.6Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. T...
CVE-2024-12136HIGH7.8Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass...
CVE-2024-13412HIGH7.5The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-13410CRITICAL9.8The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ...
CVE-2024-50631HIGH7.5Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now