2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27129HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-27128HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-27127HIGH8.8A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner...
CVE-2024-21902HIGH8.1An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operatin...
CVE-2024-1721MEDIUM5.6Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software...
CVE-2024-33529HIGH7.2ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrativ...
CVE-2024-33528MEDIUM4.7A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authentic...
CVE-2024-33527MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 bef...
CVE-2024-33526HIGH7.1A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7...
CVE-2024-4452MEDIUM5.4The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in version...
CVE-2024-35386HIGH7.5An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the m...
CVE-2024-35385MEDIUM4.3An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in ...
CVE-2024-35384MEDIUM5.5An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function i...
CVE-2024-35218MEDIUM4.8Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers tha...
CVE-2024-34071MEDIUM6.1Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirec...
CVE-2024-35361CRITICAL9.8MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL sta...
CVE-2024-35180MEDIUM6.1OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `ca...
CVE-2024-4420HIGH7.5There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3.  * An adversary can crash binari...
CVE-2024-3268MEDIUM5.3The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to...
CVE-2024-4876MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘p...
CVE-2024-4619MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cro...
CVE-2024-4361MEDIUM5.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteo...
CVE-2024-4988HIGH7.5The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to th...
CVE-2024-4700MEDIUM5.4The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-4695MEDIUM5.4The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now