2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22234HIGH7.4In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to bro...
CVE-2024-1559MEDIUM6.1The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in ...
CVE-2024-1510MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-22019HIGH7.5A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encodin...
CVE-2024-21896CRITICAL9.8The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the ...
CVE-2024-21892HIGH7.8On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the pro...
CVE-2024-21891HIGH8.8Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be ov...
CVE-2024-21890MEDIUM6.5The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last charac...
CVE-2024-0715CRITICAL9.8Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue a...
CVE-2024-1648HIGH7.5electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible beca...
CVE-2024-1647HIGH7.5Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because...
CVE-2024-1651CRITICAL9.8Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application i...
CVE-2024-1644HIGH8.8Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LF...
CVE-2024-1297HIGH7.2Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vu...
CVE-2024-26134HIGH7.5cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format...
CVE-2024-26129MEDIUM5.3PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vu...
CVE-2024-1638CRITICAL9.1The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characte...
CVE-2024-1635HIGH7.5A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protoco...
CVE-2024-25640MEDIUM5.4Iris is a web collaborative platform that helps incident responders share technical details during investigations. A sto...
CVE-2024-25636HIGH8.8Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when...
CVE-2024-25635HIGH8.8alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the gener...
CVE-2024-25634MEDIUM6.5alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other...
CVE-2024-25626CRITICAL9.8Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless...
CVE-2024-25983MEDIUM5.3Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard ...
CVE-2024-25982HIGH8.8The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now