2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25981MEDIUM5.3Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all...
CVE-2024-25980MEDIUM5.3Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other grou...
CVE-2024-25979MEDIUM5.3The URL parameters accepted by forum search were not limited to the allowed parameters.
CVE-2024-25978HIGH7.5Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
CVE-2024-1633LOW2During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_...
CVE-2024-25625CRITICAL9.3Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered...
CVE-2024-25623HIGH7.7Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and...
CVE-2024-1597CRITICAL9.8pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the ...
CVE-2024-1346MEDIUM5.5Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to cal...
CVE-2024-1345MEDIUM5.5Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to per...
CVE-2024-1344CRITICAL9.8Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read...
CVE-2024-1343MEDIUM5.5A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allow...
CVE-2024-1580HIGH8.8An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to mem...
CVE-2024-26308MEDIUM5.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache ...
CVE-2024-25710MEDIUM5.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apach...
CVE-2024-24722CRITICAL9.1An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an att...
CVE-2024-26328MEDIUM6An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIO...
CVE-2024-26327MEDIUM5.3An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where ...
CVE-2024-26318MEDIUM6.1Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / ...
CVE-2024-25113Rejected reason: This CVE was misassigned. See CVE-2023-47623 for the canonical reference.
CVE-2024-22337MEDIUM5.5IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall...
CVE-2024-22336MEDIUM5.5IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall...
CVE-2024-22335MEDIUM5.5IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall...
CVE-2024-1512CRITICAL9.8The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union base...
CVE-2024-0610CRITICAL9.8The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now