2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51319HIGH7.3A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attac...
CVE-2024-46663MEDIUM6.7A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 a...
CVE-2024-45328HIGH7.8An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged admin...
CVE-2024-45324HIGH7.2A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2...
CVE-2024-33501MEDIUM6.7Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Forti...
CVE-2024-32123MEDIUM6.7Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMan...
CVE-2024-54085CRITICAL9.8AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish H...
CVE-2024-54084HIGH7APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition ...
CVE-2024-12546Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-56336CRITICAL9.8A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0...
CVE-2024-56182HIGH8.4A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12...
CVE-2024-56181HIGH8.4A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07)...
CVE-2024-52285MEDIUM6.9A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-...
CVE-2024-28607LOW2.9The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperl...
CVE-2024-58102MEDIUM6.5An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consum...
CVE-2024-13228MEDIUM6.5The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2024-13864HIGH7.1The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-13862HIGH7.1The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise ...
CVE-2024-13853MEDIUM6.1The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13836HIGH7.1The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13615LOW3.5The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin thr...
CVE-2024-13580MEDIUM4.3The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which c...
CVE-2024-13574HIGH7.1The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-13413MEDIUM6.1The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all vers...
CVE-2024-13436MEDIUM6.1The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now