2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25130MEDIUM6.5Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.9...
CVE-2024-25129MEDIUM5.5The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser u...
CVE-2024-22547MEDIUM4.7WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).
CVE-2024-25802CRITICAL9.8SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attac...
CVE-2024-24817MEDIUM5.3Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discuss...
CVE-2024-26592HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() ...
CVE-2024-26591MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix re-attachment branch in bpf_tracing_prog_a...
CVE-2024-26590MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: erofs: fix inconsistent per-file compression format...
CVE-2024-26589HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS...
CVE-2024-26588HIGH7.8In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Prevent out-of-bounds memory access...
CVE-2024-26587MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: netdevsim: don't try to destroy PHC on VFs PH...
CVE-2024-26586MEDIUM6.7In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption Whe...
CVE-2024-25828MEDIUM4.9cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.
CVE-2024-26284MEDIUM6.1Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, ...
CVE-2024-26283HIGH7.8An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external...
CVE-2024-26282HIGH7.1Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. Th...
CVE-2024-26281MEDIUM4.7Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the cur...
CVE-2024-25851HIGH8Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in...
CVE-2024-25850CRITICAL9.8Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
CVE-2024-1563HIGH8.1An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external...
CVE-2024-26445MEDIUM6.1flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_pla...
CVE-2024-26352HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places...
CVE-2024-26351MEDIUM6.1flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_pla...
CVE-2024-26350HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_con...
CVE-2024-26349MEDIUM4.3flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_tra...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now