2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3112MEDIUM4.8The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowin...
CVE-2024-2696MEDIUM4.8The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c...
CVE-2024-2640MEDIUM5.4The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users...
CVE-2024-2430MEDIUM5.4The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcod...
CVE-2024-0974MEDIUM4.8The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could all...
CVE-2024-6677HIGH7.8Privilege escalation in uberAgent
CVE-2024-1375MEDIUM4.3The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on t...
CVE-2024-6396CRITICAL9.8A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any fi...
CVE-2024-6392MEDIUM5.4The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modificat...
CVE-2024-6468HIGH7.5Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP list...
CVE-2024-36435CRITICAL9.8An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM...
CVE-2024-6531Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe o...
CVE-2024-6681CRITICAL9.8A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affe...
CVE-2024-6485MEDIUM6.4A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vuln...
CVE-2024-6484Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe o...
CVE-2024-39553MEDIUM6.9An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allow...
CVE-2024-39552HIGH8.7An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Ju...
CVE-2024-39551HIGH8.7An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of  Juniper Networks Jun...
CVE-2024-39550HIGH7.1A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on...
CVE-2024-39549HIGH8.7A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networ...
CVE-2024-39548HIGH7.5An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an...
CVE-2024-39546HIGH7.3A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS E...
CVE-2024-39545HIGH8.7An Improper Check for Unusual or Exceptional Conditions vulnerability in the the IKE daemon (iked) of Juniper Networks J...
CVE-2024-39543HIGH7.1A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Juno...
CVE-2024-39542HIGH8.7An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now