2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6507HIGH8.1Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API
CVE-2024-5943HIGH8.8The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-32754LOW3.1Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast i...
CVE-2024-6434MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in a...
CVE-2024-6319HIGH8.8The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u...
CVE-2024-6318HIGH8.8The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u...
CVE-2024-3904HIGH8.8Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-V...
CVE-2024-39884MEDIUM6.2A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of...
CVE-2024-1574MEDIUM6.7Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in the licensing featur...
CVE-2024-1573MEDIUM5.9Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENES...
CVE-2024-1182HIGH7Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E...
CVE-2024-5641MEDIUM5.4The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2024-3639MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pos...
CVE-2024-3638MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marq...
CVE-2024-2926MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg...
CVE-2024-2385HIGH8.8The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2024-38471MEDIUM6.8Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS com...
CVE-2024-38345HIGH8.1A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is...
CVE-2024-38344MEDIUM5.4A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is ex...
CVE-2024-6284HIGH7.3In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables conf...
CVE-2024-6383MEDIUM5.3The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might atte...
CVE-2024-6464Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-53...
CVE-2024-6463Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-53...
CVE-2024-6461Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-53...
CVE-2024-39683MEDIUM6.5ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now