2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57255MEDIUM6.8An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem wi...
CVE-2024-57254MEDIUM6.8An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a cra...
CVE-2024-13743MEDIUM6.4The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_v...
CVE-2024-56171CRITICAL9.8libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleID...
CVE-2024-56000CRITICAL9.8Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issu...
CVE-2024-45783MEDIUM4.4A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERR...
CVE-2024-45781MEDIUM6.7A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string...
CVE-2024-45776MEDIUM6.7When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its ...
CVE-2024-45775MEDIUM5.2A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for...
CVE-2024-57056MEDIUM5.4Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to sys...
CVE-2024-57055MEDIUM5Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potential...
CVE-2024-45774MEDIUM6.7A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bou...
CVE-2024-56883HIGH8.1Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are no...
CVE-2024-56882MEDIUM5.4Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role pr...
CVE-2024-51505HIGH8An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race con...
CVE-2024-50609HIGH7.5An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP addre...
CVE-2024-50608HIGH7.5An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on a...
CVE-2024-4028LOW3.8A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the perm...
CVE-2024-49589MEDIUM6.5Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based...
CVE-2024-39328MEDIUM6.8Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their ...
CVE-2024-55460CRITICAL9.8A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election Syste...
CVE-2024-39327CRITICAL9.9Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing...
CVE-2024-57050Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11714. Reason: This candidate is a reservation d...
CVE-2024-57049Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2024-57046HIGH8.8A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individua...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now