2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3063MEDIUM5.4The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the output of 'tags' adde...
CVE-2024-2253MEDIUM6.4The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values ...
CVE-2024-5514CRITICAL9.8MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be r...
CVE-2024-3726MEDIUM6.4The Login Logout Register Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'llrml...
CVE-2024-36114HIGH8.6Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompr...
CVE-2024-35221MEDIUM4.3Rubygems.org is the Ruby community's gem hosting service. A Gem publisher can cause a Remote DoS when publishing a Gem. ...
CVE-2024-35492HIGH7.5Cesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c....
CVE-2024-36016HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_rece...
CVE-2024-35434HIGH7.5Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/...
CVE-2024-35512MEDIUM5.3hmq v1.5.5 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can trigger a bro...
CVE-2024-34715LOW3.3Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL d...
CVE-2024-36427HIGH8.1The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authent...
CVE-2024-35333HIGH8.4A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occ...
CVE-2024-35311LOW3.3Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 F...
CVE-2024-35284MEDIUM5.4A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthen...
CVE-2024-35283MEDIUM6.1A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticat...
CVE-2024-35200MEDIUM5.3When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX w...
CVE-2024-34161MEDIUM5.3When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maxi...
CVE-2024-32760MEDIUM6.5When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can c...
CVE-2024-31079MEDIUM4.8When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX w...
CVE-2024-28974MEDIUM6.5Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privile...
CVE-2024-4358CRITICAL9.8In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gai...
CVE-2024-36470CRITICAL9.8In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific e...
CVE-2024-36378HIGH7.5In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
CVE-2024-36377HIGH8.1In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now