2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52362MEDIUM6.5IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11...
CVE-2024-10838CRITICAL9.1An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This m...
CVE-2024-13872HIGH7.5Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Int...
CVE-2024-13871HIGH8.8A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (fir...
CVE-2024-13870MEDIUM5.7An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows...
CVE-2024-58089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_de...
CVE-2024-58088MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock when freeing cgroup storage The ...
CVE-2024-13446CRITICAL9.8The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ...
CVE-2024-13430MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure i...
CVE-2024-58087HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expir...
CVE-2024-13838LOW3.8The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2024-12589MEDIUM5.4The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Base...
CVE-2024-13498MEDIUM5.3The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Info...
CVE-2024-9157HIGH7.8** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics...
CVE-2024-56338MEDIUM4.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-...
CVE-2024-55597HIGH7.2A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 thr...
CVE-2024-55592LOW3.8An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6....
CVE-2024-55590HIGH8.8Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE...
CVE-2024-54026HIGH8.8An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 t...
CVE-2024-54018HIGH7.2Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox befo...
CVE-2024-52961HIGH8.8An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo...
CVE-2024-52960HIGH8.8A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 ...
CVE-2024-51322MEDIUM5.4Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote C...
CVE-2024-51321HIGH7.6In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to...
CVE-2024-51320MEDIUM5.4Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote C...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now