2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29439Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-31999HIGH7.4@festify/secure-session creates a secure stateless cookie session for Fastify. At the end of the request handling, it wi...
CVE-2024-31997HIGH8.8XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extension...
CVE-2024-31995MEDIUM4.3`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0....
CVE-2024-29504HIGH7.6Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code ...
CVE-2024-31996CRITICAL9.8XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc...
CVE-2024-31988HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.1...
CVE-2024-31987HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, an...
CVE-2024-31986HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1...
CVE-2024-31985MEDIUM5.4XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1...
CVE-2024-29460MEDIUM6.6An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone vi...
CVE-2024-26362HIGH8.8HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to r...
CVE-2024-1481MEDIUM5.3A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be ...
CVE-2024-31984HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10...
CVE-2024-31983HIGH8.8XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit ri...
CVE-2024-31982CRITICAL9.8XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, an...
CVE-2024-31981HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc...
CVE-2024-31939MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Import any XML or CSV File to WordPress.This issue affects Imp...
CVE-2024-31819CRITICAL9.8An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath ...
CVE-2024-31465HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9...
CVE-2024-31430HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professiona...
CVE-2024-29502MEDIUM6.5An issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC p...
CVE-2024-29500CRITICAL9.8An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary ...
CVE-2024-29269HIGH8.8An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the ...
CVE-2024-3516MEDIUM6.5Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now