2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25715MEDIUM6.1Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.
CVE-2024-25714CRITICAL9.8In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attack...
CVE-2024-1432MEDIUM5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22 and classi...
CVE-2024-1431MEDIUM6.5A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is ...
CVE-2024-23724CRITICAL9Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any acco...
CVE-2024-1430MEDIUM6.5A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vuln...
CVE-2024-22313HIGH7.8IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, ...
CVE-2024-22312MEDIUM5.5IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local u...
CVE-2024-22361HIGH7.5IBM Semeru Runtime 8.0.302.0 through 8.0.392.0, 11.0.12.0 through 11.0.21.0, 17.0.1.0 - 17.0.9.0, and 21.0.1.0 uses weak...
CVE-2024-23517MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Start Booking Sche...
CVE-2024-23516MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calculators World ...
CVE-2024-23514MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ClickToTweet.Com C...
CVE-2024-24831MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Add...
CVE-2024-24804MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in websoudan MW WP Fo...
CVE-2024-24803MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPoperation Ultra ...
CVE-2024-24801MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt OWL Caro...
CVE-2024-24717MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Kinchin Beds2...
CVE-2024-24713MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Auto Listings A...
CVE-2024-24712MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heate...
CVE-2024-1406MEDIUM4.3A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects un...
CVE-2024-0596MEDIUM5.3The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of d...
CVE-2024-0595MEDIUM4.3The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due ...
CVE-2024-0594HIGH8.8The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injectio...
CVE-2024-1405MEDIUM4.3A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown par...
CVE-2024-21490HIGH7.5This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular express...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now