2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8510MEDIUM5.3N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Custom...
CVE-2024-44866MEDIUM6.8A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary c...
CVE-2024-49561HIGH7.8Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Ass...
CVE-2024-49559HIGH8.8Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password...
CVE-2024-48831HIGH8.4Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthent...
CVE-2024-48828MEDIUM5.5Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Mana...
CVE-2024-48017MEDIUM6.5Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization...
CVE-2024-48015MEDIUM6.7Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization...
CVE-2024-48830HIGH7.8Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization...
CVE-2024-48013HIGH8.8Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecess...
CVE-2024-9055MEDIUM4.2The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allo...
CVE-2024-54027MEDIUM4.4A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and...
CVE-2024-12992CRITICAL9.8Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This ...
CVE-2024-12971HIGH8.8Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affec...
CVE-2024-13602MEDIUM4.8The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-13126MEDIUM4.6The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htac...
CVE-2024-58103MEDIUM5.8Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReade...
CVE-2024-13497MEDIUM6.1The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t...
CVE-2024-13847Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-12336MEDIUM6.5The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of ...
CVE-2024-54449HIGH8.8The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat...
CVE-2024-54448HIGH7.2The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying ...
CVE-2024-54447HIGH7.1Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time...
CVE-2024-54446HIGH7.1Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a ...
CVE-2024-54445HIGH8.7Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-base...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now