2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2892HIGH8.8A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this vulnerability is th...
CVE-2024-2452CRITICAL9.8In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cau...
CVE-2024-2214HIGH7.8In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check cau...
CVE-2024-2212HIGH7.8In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (...
CVE-2024-29833MEDIUM5.4The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by usi...
CVE-2024-29832MEDIUM6.1The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross S...
CVE-2024-29810MEDIUM5.4The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross ...
CVE-2024-29809MEDIUM5.4The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross ...
CVE-2024-29808MEDIUM5.4The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross S...
CVE-2024-26645MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing: Ensure visibility when inserting an elemen...
CVE-2024-26644MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to sn...
CVE-2024-25958HIGH7.8Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A ...
CVE-2024-25957MEDIUM5.5Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in ...
CVE-2024-25956MEDIUM5.5Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenti...
CVE-2024-21920HIGH7.1 A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyon...
CVE-2024-21919HIGH7.8 An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a malicious user to i...
CVE-2024-21918HIGH7.8 A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user...
CVE-2024-21913HIGH7.8 A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially al...
CVE-2024-21912HIGH7.8 An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert una...
CVE-2024-2802Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1166. Reason: This candidate is a r...
CVE-2024-29401CRITICAL9.8xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted a...
CVE-2024-29197MEDIUM6.5Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true...
CVE-2024-23722HIGH7.5In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content...
CVE-2024-23482HIGH7.8The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fi...
CVE-2024-22356MEDIUM4.9IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now