2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22127CRITICAL9.1SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high priv...
CVE-2024-28199MEDIUM6.1phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting ...
CVE-2024-28120HIGH7.5codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-ch...
CVE-2024-27938MEDIUM5.3Postal is an open source SMTP server. Postal versions less than 3.0.0 are vulnerable to SMTP Smuggling attacks which may...
CVE-2024-27297MEDIUM5.9Nix is a package manager for Linux and other Unix systems. A fixed-output derivations on Linux can send file descriptors...
CVE-2024-25854MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbit...
CVE-2024-25114MEDIUM5.3Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Onli...
CVE-2024-1645MEDIUM4.3The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on ...
CVE-2024-1400MEDIUM4.3The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability...
CVE-2024-2357MEDIUM6.5The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a...
CVE-2024-28198HIGH7.5OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manual...
CVE-2024-28197HIGH7.5Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its...
CVE-2024-28187HIGH7.2SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versi...
CVE-2024-27237MEDIUM5.5In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This ...
CVE-2024-27236HIGH8.4In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local es...
CVE-2024-27235MEDIUM5.5In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to loca...
CVE-2024-27234MEDIUM5.9In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to loc...
CVE-2024-27233HIGH7.8In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to ...
CVE-2024-27230MEDIUM5.1In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a...
CVE-2024-27229HIGH7.5In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null...
CVE-2024-27228CRITICAL9.8there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no ...
CVE-2024-27227CRITICAL9.8A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues
CVE-2024-27226HIGH8.4In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to ...
CVE-2024-27225MEDIUM4.4In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could ...
CVE-2024-27224HIGH7.8In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now