2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1316MEDIUM6.5The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does...
CVE-2024-2048CRITICAL9.8Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con...
CVE-2024-27889HIGH8.8Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista ...
CVE-2024-27199HIGH7.3In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
CVE-2024-27198CRITICAL9.8In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
CVE-2024-27694HIGH7.4FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_cate...
CVE-2024-27680MEDIUM6.1Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."
CVE-2024-27668MEDIUM6.1Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'
CVE-2024-0686Rejected reason: Incorrect assignment
CVE-2024-27684MEDIUM6.1A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTA...
CVE-2024-24901LOW2.3Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with h...
CVE-2024-22463CRITICAL9.1Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A...
CVE-2024-22452HIGH7.8Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low priv...
CVE-2024-1788Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2813. Reason: This candidate is a d...
CVE-2024-0156HIGH7.8Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attack...
CVE-2024-0155HIGH7.8Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacke...
CVE-2024-26622HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tomoyo: fix UAF write bug in tomoyo_write_control()...
CVE-2024-21826MEDIUM5.5in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storag...
CVE-2024-21816MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of ...
CVE-2024-20038LOW3.4In pq, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information dis...
CVE-2024-20037MEDIUM6.7In pq, there is a possible write-what-where condition due to an incorrect bounds check. This could lead to local escalat...
CVE-2024-20036MEDIUM4.4In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclos...
CVE-2024-20034HIGH7.2In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalati...
CVE-2024-20033MEDIUM4.4In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information...
CVE-2024-20032MEDIUM6.7In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now