2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1224HIGH7.1This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user logi...
CVE-2024-2211MEDIUM6.1Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacke...
CVE-2024-26628Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-26627MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: core: Move scsi_host_busy() out of host lock ...
CVE-2024-26626MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packet...
CVE-2024-26625HIGH7.8In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot rep...
CVE-2024-26624Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-26623MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq ...
CVE-2024-1989MEDIUM5.4The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-1771MEDIUM4.3The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th...
CVE-2024-1760MEDIUM4.7The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cro...
CVE-2024-1220HIGH7.5A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and pri...
CVE-2024-27278MEDIUM5.4OpenPNE Plugin "opTimelinePlugin" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which us...
CVE-2024-25817HIGH7.8Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .gi...
CVE-2024-22889HIGH7.5Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the webs...
CVE-2024-27765HIGH7.5Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information vi...
CVE-2024-27764CRITICAL9.8An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
CVE-2024-24786HIGH7.5The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condit...
CVE-2024-24785MEDIUM5.4If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-...
CVE-2024-24784HIGH7.5The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is...
CVE-2024-24783MEDIUM5.9Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.V...
CVE-2024-24278HIGH7.5An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive informa...
CVE-2024-24276CRITICAL9.6Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote atta...
CVE-2024-24275CRITICAL9.6Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker t...
CVE-2024-1901MEDIUM4.3Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now