2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34488HIGH7.5OFPMultipartReply in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via ...
CVE-2024-34487HIGH7.5OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst....
CVE-2024-34486HIGH7.5OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFP...
CVE-2024-34484MEDIUM5.3OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.l...
CVE-2024-34483HIGH7.5OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via ...
CVE-2024-4492HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). This issue affects the fu...
CVE-2024-34478HIGH7.5btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptibl...
CVE-2024-4491HIGH8.8A vulnerability classified as critical was found in Tenda i21 1.0.0.14(4656). This vulnerability affects the function fo...
CVE-2024-34476MEDIUM5.3Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_...
CVE-2024-34475HIGH7.5Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_...
CVE-2024-34473MEDIUM5.3An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message t...
CVE-2024-34469HIGH7.1Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
CVE-2024-34468MEDIUM6.1Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.
CVE-2024-34467MEDIUM6.1ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_e...
CVE-2024-34462MEDIUM6.1Alinto SOGo through 5.10.0 allows XSS during attachment preview.
CVE-2024-1050MEDIUM4.3The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2024-34461CRITICAL9.8Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY ele...
CVE-2024-34460MEDIUM6.5The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5...
CVE-2024-3240HIGH8.8The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 ...
CVE-2024-3237MEDIUM5.4The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2024-3868MEDIUM5.4The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name ...
CVE-2024-34455HIGH7.5Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2.
CVE-2024-34453MEDIUM4.3TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity...
CVE-2024-34075MEDIUM6.2kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the ...
CVE-2024-34068MEDIUM6.4Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game serv...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now