2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11283HIGH7.5The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th...
CVE-2024-55549HIGH7.8xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.
CVE-2024-55060MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to exe...
CVE-2024-30143MEDIUM4.3HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing...
CVE-2024-9042MEDIUM5.9This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff...
CVE-2024-53406HIGH8.8Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection p...
CVE-2024-12858Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. *** Duplicate of CVE-2025-2...
CVE-2024-57062MEDIUM6.7An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive info...
CVE-2024-55198MEDIUM5.3User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct...
CVE-2024-57348MEDIUM6.1Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary c...
CVE-2024-28803MEDIUM6.1Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote att...
CVE-2024-22880MEDIUM4.7Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary...
CVE-2024-10942HIGH7.5The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,...
CVE-2024-8402HIGH7.4An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from...
CVE-2024-7296LOW2.7An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 pr...
CVE-2024-13891HIGH7.1The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13885HIGH7.1The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-13884HIGH7.1The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13054MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17...
CVE-2024-12380HIGH7.5An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f...
CVE-2024-13887MEDIUM5.3The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Di...
CVE-2024-13703MEDIUM4.3The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2024-26290HIGH8.7Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Av...
CVE-2024-34398MEDIUM4.2An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated...
CVE-2024-27763MEDIUM5.3XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostna...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now