2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24926HIGH8.8Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress T...
CVE-2024-24797CRITICAL9.8Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue...
CVE-2024-24796HIGH8.8Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooComme...
CVE-2024-23513CRITICAL9.8Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.
CVE-2024-25100CRITICAL9.8Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue ...
CVE-2024-24889MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All ...
CVE-2024-24933MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Ho...
CVE-2024-24932MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Grou...
CVE-2024-24931MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in swadeshswain Befor...
CVE-2024-24930MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes.Com Butt...
CVE-2024-24928MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arunas Liuiza Cont...
CVE-2024-24927MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnitedThemes Brook...
CVE-2024-25744HIGH8.8In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is relate...
CVE-2024-25741MEDIUM5.5printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep...
CVE-2024-25740MEDIUM5.5A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOC...
CVE-2024-25739MEDIUM5.5create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and cr...
CVE-2024-1433LOW3.7A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the f...
CVE-2024-25728HIGH7.5ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configur...
CVE-2024-25419HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_men...
CVE-2024-25418HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_men...
CVE-2024-25417HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_transl...
CVE-2024-1151MEDIUM5.5A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive ope...
CVE-2024-21875MEDIUM6.5Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team H...
CVE-2024-25722CRITICAL9.8qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.
CVE-2024-25718CRITICAL9.8In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which int...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now