2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26593HIGH7.1In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Fix block process call transactions Acc...
CVE-2024-1590MEDIUM5.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-0563MEDIUM6.5Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous...
CVE-2024-1779MEDIUM5.3The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-1778MEDIUM5.3The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-1777MEDIUM4.3The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v...
CVE-2024-1776HIGH7.2The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' par...
CVE-2024-22243HIGH8.1Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perf...
CVE-2024-1786HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 ...
CVE-2024-1784MEDIUM6.6A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown funct...
CVE-2024-1783CRITICAL9.8A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. ...
CVE-2024-1781CRITICAL9.8A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affe...
CVE-2024-1683HIGH7.3 A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application fil...
CVE-2024-25756HIGH8A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote...
CVE-2024-25753HIGH8.8Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote a...
CVE-2024-25748HIGH8.8A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a re...
CVE-2024-26152MEDIUM6.1### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitize...
CVE-2024-25746HIGH8.8Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote a...
CVE-2024-25369MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted...
CVE-2024-1750HIGH8.1A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_u...
CVE-2024-1749MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Bdtask Bhojon Best Restaurant Management Softwar...
CVE-2024-1748HIGH7.5A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects ...
CVE-2024-26151MEDIUM5.4The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a ma...
CVE-2024-26128MEDIUM5.4baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in th...
CVE-2024-25385MEDIUM6.2An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 functi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now