2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12971HIGH8.8Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affec...
CVE-2024-13602MEDIUM4.8The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-13126MEDIUM4.6The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htac...
CVE-2024-58103MEDIUM5.8Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReade...
CVE-2024-13497MEDIUM6.1The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t...
CVE-2024-13847——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-12336MEDIUM6.5The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of ...
CVE-2024-54449HIGH8.8The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat...
CVE-2024-54448HIGH7.2The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying ...
CVE-2024-54447HIGH7.1Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time...
CVE-2024-54446HIGH7.1Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a ...
CVE-2024-54445HIGH8.7Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-base...
CVE-2024-29409MEDIUM5.5File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Typ...
CVE-2024-12245HIGH8.7Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-bas...
CVE-2024-12020MEDIUM6.1There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica...
CVE-2024-12019HIGH7.1The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read...
CVE-2024-55594CRITICAL9.8An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7...
CVE-2024-40585MEDIUM6.5An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2...
CVE-2024-47573MEDIUM6.5An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2...
CVE-2024-46662HIGH8.8A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions ...
CVE-2024-45643HIGH7.5IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt ...
CVE-2024-45638MEDIUM4.4IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
CVE-2024-40590MEDIUM4.8An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio...
CVE-2024-13773HIGH7.5The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information...
CVE-2024-13772MEDIUM5.9The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now