2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24708MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a thro...
CVE-2024-24701HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-base...
CVE-2024-24155MEDIUM6.5Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42a...
CVE-2024-24150MEDIUM6.5A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service vi...
CVE-2024-24149MEDIUM6.5A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service vi...
CVE-2024-24147MEDIUM6.5A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of servic...
CVE-2024-24146MEDIUM6.5A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service ...
CVE-2024-23946MEDIUM5.3Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, t...
CVE-2024-23807CRITICAL9.8The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the sca...
CVE-2024-23519HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before ...
CVE-2024-23328CRITICAL9.1Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase data...
CVE-2024-23302HIGH7.5Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
CVE-2024-23052CRITICAL9.8An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the...
CVE-2024-22939HIGH8.8Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the syst...
CVE-2024-22936MEDIUM6.1Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIM...
CVE-2024-22251MEDIUM4.4VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). ...
CVE-2024-21726MEDIUM6.5Inadequate content filtering leads to XSS vulnerabilities in various components.
CVE-2024-21725MEDIUM6.1Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
CVE-2024-21724MEDIUM6.1Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
CVE-2024-21723MEDIUM4.3Inadequate parsing of URLs could result into an open redirect.
CVE-2024-21722MEDIUM6.3The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modifi...
CVE-2024-20344MEDIUM5.3A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersi...
CVE-2024-20321HIGH8.6A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an una...
CVE-2024-20294MEDIUM6.6A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software coul...
CVE-2024-20291MEDIUM5.8A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now