2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2247MEDIUM6.1JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handli...
CVE-2024-28684HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_...
CVE-2024-28675HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php
CVE-2024-26629MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: fix RELEASE_LOCKOWNER The test on so_count i...
CVE-2024-1508MEDIUM5.4The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'setti...
CVE-2024-1507MEDIUM5.4The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title...
CVE-2024-28668MEDIUM6.1DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychann...
CVE-2024-28667MEDIUM6.1DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templet...
CVE-2024-28666MEDIUM5.5DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/media_a...
CVE-2024-28665HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article...
CVE-2024-28432HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article...
CVE-2024-28431HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog...
CVE-2024-28430MEDIUM6.1DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog...
CVE-2024-28429MEDIUM5.5DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archive...
CVE-2024-2416MEDIUM6.5Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnera...
CVE-2024-2415HIGH7.8Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allo...
CVE-2024-2414HIGH8.8The primary channel is unprotected on Movistar 4G router affecting E version S_WLD71-T1_v2.0.201820. This device has the...
CVE-2024-2123MEDIUM6.1The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-1979LOW3.5A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvert...
CVE-2024-28623MEDIUM6.1RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec...
CVE-2024-26529HIGH7.5An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) vi...
CVE-2024-27440MEDIUM4.8The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3....
CVE-2024-2400HIGH8.8Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially ...
CVE-2024-2413CRITICAL9.8Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string...
CVE-2024-2412MEDIUM5.3The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now