2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-56310HIGH8.8REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery...
CVE-2024-12891HIGH8.8A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an ...
CVE-2024-12890HIGH8.8A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue a...
CVE-2024-12771HIGH8.8The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-12721HIGH7.2The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
CVE-2024-12066HIGH8.8The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ...
CVE-2024-11977HIGH7.3The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-56335HIGH7.5vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve...
CVE-2024-56334HIGH7.8systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when ...
CVE-2024-56329HIGH8.9Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffo...
CVE-2024-12867HIGH8.8Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthent...
CVE-2024-37758HIGH8.8Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attacker...
CVE-2024-12677HIGH8.5Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.
CVE-2024-55470HIGH7.5Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can ...
CVE-2024-10385HIGH8.6Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-p...
CVE-2024-56356HIGH7.1In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
CVE-2024-56351HIGH8.8In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
CVE-2024-40695HIGH8IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file uplo...
CVE-2024-28767HIGH8.8IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated at...
CVE-2024-11297HIGH7.5The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2024-21549HIGH8.6Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL ...
CVE-2024-44195HIGH7.5A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to r...
CVE-2024-54538HIGH7.5A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17....
CVE-2024-12831HIGH7.8Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local...
CVE-2024-12830HIGH7.3Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows rem...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now