2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34789MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Hait Pos...
CVE-2024-34754MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue aff...
CVE-2024-3829CRITICAL9.1qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Att...
CVE-2024-35635MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from...
CVE-2024-35633MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affec...
CVE-2024-23670HIGH8.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,...
CVE-2024-23668HIGH8.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,...
CVE-2024-23667HIGH8.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,...
CVE-2024-23665HIGH8.8Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, ...
CVE-2024-23664MEDIUM6.1A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and be...
CVE-2024-23363HIGH7.5Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.
CVE-2024-23360HIGH7.8Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
CVE-2024-21478MEDIUM5.5transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
CVE-2024-5404CRITICAL9.8An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mech...
CVE-2024-35639MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple ...
CVE-2024-35638MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in JumpDEMAND Inc. ActiveDEMAND.This issue affects ActiveDEMAND: from n/...
CVE-2024-35637MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin...
CVE-2024-36964MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2...
CVE-2024-36963HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permission...
CVE-2024-36962MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Queue RX packets in IRQ handler instea...
CVE-2024-36961MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Fix two locking issues with therma...
CVE-2024-36960HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled eve...
CVE-2024-35640MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tomas Corde...
CVE-2024-31493MEDIUM6.5An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3...
CVE-2024-23107MEDIUM5.5An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now