2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26468MEDIUM6.1A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b6...
CVE-2024-26467MEDIUM6.1A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams befo...
CVE-2024-26466MEDIUM6.1A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform...
CVE-2024-26465MEDIUM6.1A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before...
CVE-2024-25925CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees ...
CVE-2024-25913CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a ...
CVE-2024-25909HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media ...
CVE-2024-25763MEDIUM5.5openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.
CVE-2024-25760Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-25410MEDIUM6.5flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.
CVE-2024-25344MEDIUM6.1Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remto...
CVE-2024-25082MEDIUM6.5Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
CVE-2024-25081MEDIUM4.2Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
CVE-2024-24714HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons...
CVE-2024-24568MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P...
CVE-2024-23839HIGH8.1Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P...
CVE-2024-23837HIGH7.5LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP hea...
CVE-2024-23836HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-23835HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P...
CVE-2024-23605CRITICAL9.8A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2...
CVE-2024-23496CRITICAL9.8A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 1...
CVE-2024-22873HIGH8.1Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subs...
CVE-2024-22371HIGH7.5Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that expo...
CVE-2024-22201HIGH7.5Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will...
CVE-2024-21836CRITICAL9.8A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now