2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28607LOW2.9The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperl...
CVE-2024-58102MEDIUM6.5An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consum...
CVE-2024-13228MEDIUM6.5The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2024-13864HIGH7.1The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-13862HIGH7.1The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise ...
CVE-2024-13853MEDIUM6.1The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13836HIGH7.1The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13615LOW3.5The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin thr...
CVE-2024-13580MEDIUM4.3The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which c...
CVE-2024-13574HIGH7.1The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-13413MEDIUM6.1The ProductDyno plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘res’ parameter in all vers...
CVE-2024-13436MEDIUM6.1The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-12010HIGH7.2A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware v...
CVE-2024-12009HIGH7.2A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5....
CVE-2024-11253HIGH7.2A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyx...
CVE-2024-49823MEDIUM6.5IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of servic...
CVE-2024-41760LOW3.7IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due...
CVE-2024-22340MEDIUM6.5IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive informa...
CVE-2024-56192HIGH7.8In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This co...
CVE-2024-56191HIGH8.4In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to lo...
CVE-2024-56188MEDIUM5.1there is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with...
CVE-2024-56187MEDIUM6.6In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the...
CVE-2024-56186MEDIUM5.1In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This ...
CVE-2024-56185MEDIUM5.1In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-of-bounds read due to...
CVE-2024-56184MEDIUM5.1In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now