2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26246LOW3.9Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2024-26163MEDIUM4.7Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2024-1853MEDIUM5.5Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x8000...
CVE-2024-2249MEDIUM5.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWr...
CVE-2024-26503CRITICAL9.1Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to ...
CVE-2024-26475MEDIUM5.5An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of ...
CVE-2024-2256MEDIUM5.4The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact...
CVE-2024-1713HIGH7.2A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as t...
CVE-2024-0860HIGH7.5 The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow ...
CVE-2024-28425HIGH7.5greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/...
CVE-2024-28424HIGH8.8zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cl...
CVE-2024-28423CRITICAL9.8Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at ...
CVE-2024-27301HIGH7.3Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability i...
CVE-2024-27266HIGH8.2IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML ...
CVE-2024-27265MEDIUM6.5IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an atta...
CVE-2024-24770MEDIUM5.3vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le...
CVE-2024-24562MEDIUM5.3vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers ar...
CVE-2024-23823MEDIUM6.5vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le...
CVE-2024-22346HIGH7.8Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqua...
CVE-2024-28181HIGH8.1 turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoo...
CVE-2024-1998Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1795. Reason: This candidate is a r...
CVE-2024-28849MEDIUM6.5follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows...
CVE-2024-25139CRITICAL10In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads t...
CVE-2024-28323MEDIUM6.5The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a pot...
CVE-2024-25156MEDIUM6.5 A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-sp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now