2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28716HIGH7.5An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.
CVE-2024-25938HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially craft...
CVE-2024-25648HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially craf...
CVE-2024-25575HIGH8.8A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A spec...
CVE-2024-23774HIGH7.8An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerabi...
CVE-2024-23773HIGH7.8An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability ex...
CVE-2024-23772MEDIUM6.6An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability ex...
CVE-2024-2617HIGH7.2A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if se...
CVE-2024-2378HIGH8A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privil...
CVE-2024-2377HIGH7.6A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can tak...
CVE-2024-4337HIGH7.4Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti...
CVE-2024-4336HIGH7.4Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti...
CVE-2024-22405MEDIUM5.5XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted...
CVE-2024-4185HIGH8.1The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authenticat...
CVE-2024-3072MEDIUM4.3The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-2663HIGH8.3The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i...
CVE-2024-1895HIGH7.5The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object I...
CVE-2024-4225HIGH7.6Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), b...
CVE-2024-31837HIGH8.4DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE...
CVE-2024-1371MEDIUM6.5The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capabi...
CVE-2024-4226LOW3.5It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all use...
CVE-2024-0216MEDIUM6.4The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in v...
CVE-2024-4327LOW3.5A vulnerability was found in Apryse WebViewer up to 10.8.0. It has been classified as problematic. This affects an unkno...
CVE-2024-34050HIGH7.5Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<...
CVE-2024-34049HIGH7.5Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now