2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6306Rejected reason: **REJECT** Accidental Reservation making this a duplicate. Please use CVE-2024-32111.
CVE-2024-6305Rejected reason: **REJECT** Accidental Reservation making this a duplicate. Please use CVE-2024-31111.
CVE-2024-5216HIGH7.5A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resourc...
CVE-2024-4641CRITICAL9.8OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format...
CVE-2024-4640HIGH8.2OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds che...
CVE-2024-4639HIGH8.8OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutrali...
CVE-2024-6028CRITICAL9.8The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all v...
CVE-2024-4638HIGH8.8OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutrali...
CVE-2024-34142MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-34141MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-3249MEDIUM4.3The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2024-5431HIGH8.8The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is v...
CVE-2024-4759MEDIUM5.5The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with...
CVE-2024-4757HIGH8.1The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanit...
CVE-2024-6297CRITICAL10Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A m...
CVE-2024-4197CRITICAL9.8An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code exec...
CVE-2024-4196CRITICAL9.8An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code ex...
CVE-2024-37007HIGH7.8A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after...
CVE-2024-37006HIGH7.8A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory cor...
CVE-2024-37005HIGH7.8A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Rea...
CVE-2024-37004HIGH7.8A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-f...
CVE-2024-37003HIGH7.8A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications,...
CVE-2024-36999HIGH7.8A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds W...
CVE-2024-32855MEDIUM4.4Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high pri...
CVE-2024-23159HIGH7.8A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to unini...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now