2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39220MEDIUM6.5BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, A...
CVE-2024-6471HIGH8.8A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affe...
CVE-2024-37726MEDIUM6.8Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to...
CVE-2024-32937CRITICAL9.8An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9....
CVE-2024-6470LOW2.7A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown fun...
CVE-2024-5672HIGH7.2A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization ...
CVE-2024-6427HIGH7.5Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can u...
CVE-2024-6426HIGH7.1Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacke...
CVE-2024-6469HIGH8.8A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an un...
CVE-2024-6428MEDIUM6.5Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when cre...
CVE-2024-39830MEDIUM5.9Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled,...
CVE-2024-39807MEDIUM5.3Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an...
CVE-2024-39361MEDIUM5.4Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a Rem...
CVE-2024-39353LOW2.7Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them ...
CVE-2024-36257MEDIUM5.3Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to...
CVE-2024-6340MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun...
CVE-2024-6263MEDIUM5.4The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver...
CVE-2024-4482MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-38453HIGH7.5The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current vers...
CVE-2024-37082CRITICAL9.1When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be po...
CVE-2024-2376HIGH8.8The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to ...
CVE-2024-2375MEDIUM5.4The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could all...
CVE-2024-2235MEDIUM4.3The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make use...
CVE-2024-2234MEDIUM5.4The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high pr...
CVE-2024-2233MEDIUM4.3The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make log...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now