2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38301HIGH7.8Dell Alienware Command Center, version 5.7.3.0 and prior, contains an improper access control vulnerability. A low privi...
CVE-2024-5792HIGH8.8The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all...
CVE-2024-5677MEDIUM4.3The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability...
CVE-2024-4866MEDIUM5.4The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere El...
CVE-2024-22018LOW2.9A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs...
CVE-2024-6433HIGH7.5The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files...
CVE-2024-32670HIGH7Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes ...
CVE-2024-25023MEDIUM5.5IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores p...
CVE-2024-21417HIGH8.8Windows Text Services Framework Elevation of Privilege Vulnerability
CVE-2024-22477MEDIUM4.3A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained ...
CVE-2024-22377MEDIUM5.3The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
CVE-2024-21832LOW3.5A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON re...
CVE-2024-39901MEDIUM5.4OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the Op...
CVE-2024-39900MEDIUM5.4OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the...
CVE-2024-39883HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-...
CVE-2024-39882HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of a...
CVE-2024-39881HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption cond...
CVE-2024-39880HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-...
CVE-2024-39069HIGH7.8An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hij...
CVE-2024-38963MEDIUM6.1Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProduct...
CVE-2024-36676HIGH7.5Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targ...
CVE-2024-35154HIGH7.2IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to t...
CVE-2024-21993MEDIUM6.5SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to di...
CVE-2024-39181MEDIUM6.5Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid pa...
CVE-2024-39072MEDIUM5.5AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calend...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now