2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29863HIGH7.8A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR...
CVE-2024-26329MEDIUM6.2Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBy...
CVE-2024-29672HIGH8.8Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code v...
CVE-2024-27448CRITICAL9.1MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading t...
CVE-2024-22363HIGH7.5SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
CVE-2024-2509MEDIUM6.5The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block opt...
CVE-2024-3321MEDIUM4.8A vulnerability classified as problematic has been found in SourceCodester eLearning System 1.0. This affects an unknown...
CVE-2024-3320MEDIUM6.1A vulnerability was found in SourceCodester eLearning System 1.0. It has been rated as problematic. Affected by this iss...
CVE-2024-31498HIGH8.8Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation b...
CVE-2024-31212HIGH7.2InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2...
CVE-2024-31211CRITICAL9.8WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows f...
CVE-2024-31210HIGH8.8WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be sub...
CVE-2024-31206HIGH8.2dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `dectalk-tts@1.0.0`, network requests to th...
CVE-2024-27981CRITICAL9.8A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (V...
CVE-2024-21894CRITICAL9.8A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an...
CVE-2024-3316HIGH8.8A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical....
CVE-2024-29981MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-29049MEDIUM4.7Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
CVE-2024-3315CRITICAL9.8A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been classified as critica...
CVE-2024-3314CRITICAL9.8A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This i...
CVE-2024-3311HIGH8.8A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability...
CVE-2024-31204MEDIUM6.1mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie...
CVE-2024-30270MEDIUM6.2mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie...
CVE-2024-30264CRITICAL9.3Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prio...
CVE-2024-30255HIGH7.5Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now