2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35197MEDIUM5.4gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from ...
CVE-2024-1803MEDIUM4.3The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute...
CVE-2024-34060HIGH8.8IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-ev...
CVE-2024-28188MEDIUM5.3Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda en...
CVE-2024-26139HIGH8.1OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observ...
CVE-2024-5258MEDIUM4.3An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 b...
CVE-2024-4575MEDIUM6.4The LayerSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ls_search_form shortc...
CVE-2024-4378MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's menu...
CVE-2024-3997MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is ...
CVE-2024-1947MEDIUM6.5A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 16.10.6, 16...
CVE-2024-1815MEDIUM5.4The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-1814MEDIUM5.4The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-5165MEDIUM5.4In Eclipse Ditto versions 3.0.0 to 3.5.5, the user input of several input fields of the Eclipse Ditto Explorer User Int...
CVE-2024-4779HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injecti...
CVE-2024-2861MEDIUM5.4The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widge...
CVE-2024-5264MEDIUM6.5Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to acces...
CVE-2024-35223MEDIUM5.3Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the ap...
CVE-2024-35186HIGH8.8gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to...
CVE-2024-32969LOW2.7vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra or...
CVE-2024-30280HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when ...
CVE-2024-30279HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that...
CVE-2024-4706MEDIUM6.4The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-5241MEDIUM5.1A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been cla...
CVE-2024-5240MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This ...
CVE-2024-4835HIGH8.2A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now