2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8402HIGH7.4An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from...
CVE-2024-7296LOW2.7An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 pr...
CVE-2024-13891HIGH7.1The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13885HIGH7.1The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-13884HIGH7.1The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13054MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17...
CVE-2024-12380HIGH7.5An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f...
CVE-2024-13887MEDIUM5.3The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Di...
CVE-2024-13703MEDIUM4.3The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2024-26290HIGH8.7Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Av...
CVE-2024-34398MEDIUM4.2An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated...
CVE-2024-27763MEDIUM5.3XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostna...
CVE-2024-52362MEDIUM6.5IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11...
CVE-2024-10838CRITICAL9.1An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This m...
CVE-2024-13872HIGH7.5Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Int...
CVE-2024-13871HIGH8.8A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (fir...
CVE-2024-13870MEDIUM5.7An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows...
CVE-2024-58089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_de...
CVE-2024-58088MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock when freeing cgroup storage The ...
CVE-2024-13446CRITICAL9.8The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ...
CVE-2024-13430MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure i...
CVE-2024-58087HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expir...
CVE-2024-13838LOW3.8The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2024-12589MEDIUM5.4The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Base...
CVE-2024-13498MEDIUM5.3The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Info...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now