2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29409MEDIUM5.5File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Typ...
CVE-2024-12245HIGH8.7Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-bas...
CVE-2024-12020MEDIUM6.1There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica...
CVE-2024-12019HIGH7.1The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read...
CVE-2024-55594CRITICAL9.8An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7...
CVE-2024-40585MEDIUM6.5An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2...
CVE-2024-47573MEDIUM6.5An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2...
CVE-2024-46662HIGH8.8A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions ...
CVE-2024-45643HIGH7.5IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt ...
CVE-2024-45638MEDIUM4.4IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
CVE-2024-40590MEDIUM4.8An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio...
CVE-2024-13773HIGH7.5The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information...
CVE-2024-13772MEDIUM5.9The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass...
CVE-2024-13771MEDIUM5.9The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass...
CVE-2024-12810HIGH8.1The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat...
CVE-2024-26006MEDIUM6.1An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below...
CVE-2024-8176HIGH7.5A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XM...
CVE-2024-13407MEDIUM6.5The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via...
CVE-2024-13321CRITICAL9.8The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to...
CVE-2024-13824CRITICAL9.8The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions ...
CVE-2024-13913HIGH8.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2024-13376HIGH8.8The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat...
CVE-2024-11286CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th...
CVE-2024-11285CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an...
CVE-2024-11284CRITICAL9.8The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now