2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31898MEDIUM5.4IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypa...
CVE-2024-28797MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to ...
CVE-2024-35119MEDIUM5.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2024-31902HIGH8.8IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec...
CVE-2024-28798MEDIUM6.1IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2024-5062MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability ...
CVE-2024-28795MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2024-6415MEDIUM5.1A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is a...
CVE-2024-6414MEDIUM6.9A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown fun...
CVE-2024-5926CRITICAL9.1A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbit...
CVE-2024-39848CRITICAL9.1Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is rela...
CVE-2024-39846LOW3.5NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthoriz...
CVE-2024-39840HIGH8.8Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the...
CVE-2024-2386HIGH8.8The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' paramete...
CVE-2024-25943CRITICAL9.8iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a sessi...
CVE-2024-5819MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Store...
CVE-2024-6363MEDIUM5.4The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortco...
CVE-2024-5790MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute...
CVE-2024-5666MEDIUM5.4The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter w...
CVE-2024-6265CRITICAL9.8The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ...
CVE-2024-5942MEDIUM5.4The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an...
CVE-2024-5889MEDIUM6.1The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2024-5598HIGH7.5The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an...
CVE-2024-5192MEDIUM5.4The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps ...
CVE-2024-6405MEDIUM5.4The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now