2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50630HIGH7.5Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4...
CVE-2024-50629MEDIUM5.3Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1...
CVE-2024-12922CRITICAL9.8The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation ...
CVE-2024-12295HIGH8.8The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers...
CVE-2024-11131CRITICAL9.8A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute ar...
CVE-2024-10442CRITICAL10Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0...
CVE-2024-10445MEDIUM5.3Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-653...
CVE-2024-10444HIGH7.5Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-4...
CVE-2024-10441CRITICAL9.8Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before...
CVE-2024-57151MEDIUM6.8SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via...
CVE-2024-12563HIGH8.8The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214...
CVE-2024-56347CRITICAL9.6IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary comma...
CVE-2024-56346CRITICAL10IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improp...
CVE-2024-57170MEDIUM6.5SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" paramete...
CVE-2024-57169CRITICAL9.8A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability...
CVE-2024-49822MEDIUM4.1IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authentica...
CVE-2024-44314MEDIUM6.5TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthor...
CVE-2024-44313HIGH8.1TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which ...
CVE-2024-8997CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Confi...
CVE-2024-21760HIGH8.4An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4...
CVE-2024-41975MEDIUM5.3An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs p...
CVE-2024-23943CRITICAL9.1An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical funct...
CVE-2024-23942HIGH7.1A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an att...
CVE-2024-56506——Rejected reason: Not used
CVE-2024-56505——Rejected reason: Not used

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now