2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-9752LOW3.3Tungsten Automation Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili...
CVE-2024-9749LOW3.3Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili...
CVE-2024-52814LOW2.8Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the...
CVE-2024-45719LOW2.6Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The id...
CVE-2024-52054LOW2.7Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an ...
CVE-2024-51337LOW3.5Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain ...
CVE-2024-10515LOW3.5In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that...
CVE-2024-51671LOW2.7Missing Authorization vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Exploiting Incorrectly Conf...
CVE-2024-47820LOW3.5MarkUs, a web application for the submission and grading of student assignments, is vulnerable to path traversal in vers...
CVE-2024-5030LOW3.8The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, w...
CVE-2024-52514LOW3.5Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being bloc...
CVE-2024-46383LOW2.4Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected ...
CVE-2024-10977LOW3.7Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnis...
CVE-2024-38660LOW3.8Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated u...
CVE-2024-32667LOW3.9Out-of-bounds read for some OpenCL(TM) software may allow an authenticated user to potentially enable denial of service ...
CVE-2024-28051LOW2.2Out-of-bounds read in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially en...
CVE-2024-28030LOW2.2NULL pointer dereference in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentia...
CVE-2024-35274LOW2.3An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2024-9842LOW3.3Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to crea...
CVE-2024-51749LOW3.5Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.8...
CVE-2024-11126LOW3.1A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown fun...
CVE-2024-47799LOW3.5Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firm...
CVE-2024-48838LOW3.3Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Acc...
CVE-2024-10672LOW2.7The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie...
CVE-2024-47587LOW3.5Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of pri...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now