2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6146HIGH8.8Actiontec WCB6200Q uh_get_postdata_withupload Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...
CVE-2024-6145HIGH8.8Actiontec WCB6200Q Cookie Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent ...
CVE-2024-6144HIGH8.8Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2024-6143HIGH8.8Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows net...
CVE-2024-6142HIGH8.8Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ne...
CVE-2024-5970MEDIUM6.4The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shor...
CVE-2024-6129LOW3.7A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function ...
CVE-2024-6128MEDIUM5.3A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unk...
CVE-2024-38277MEDIUM5.4A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used inte...
CVE-2024-38276HIGH8.8Incorrect CSRF token checks resulted in multiple CSRF risks.
CVE-2024-38275HIGH7.5The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header ...
CVE-2024-38274MEDIUM6.1Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
CVE-2024-38273MEDIUM5.4Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not ha...
CVE-2024-37821HIGH8.8An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attacker...
CVE-2024-36977MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Wait unconditionally after issuing EndXf...
CVE-2024-36976MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-ctrls: show all owned controls ...
CVE-2024-36975MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Do not use WARN when encode fails W...
CVE-2024-36974HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_...
CVE-2024-37791MEDIUM6DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/ind...
CVE-2024-22002HIGH7.8CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdi...
CVE-2024-38351MEDIUM5.4Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise ...
CVE-2024-38348HIGH8.8CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the ...
CVE-2024-38347HIGH8.8CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the ...
CVE-2024-37904MEDIUM5.7Minder is an open source Software Supply Chain Security Platform. Minder's Git provider is vulnerable to a denial of ser...
CVE-2024-37803MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now