2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24397MEDIUM5.4Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker...
CVE-2024-23054CRITICAL9.8An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution du...
CVE-2024-0323CRITICAL9.8The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TL...
CVE-2024-24768HIGH7.51Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the p...
CVE-2024-24762HIGH7.5`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular E...
CVE-2024-23109CRITICAL9.8An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2024-23108CRITICAL9.8An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2024-1225CRITICAL9.8A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is t...
CVE-2024-24864MEDIUM4.7A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null po...
CVE-2024-24861MEDIUM6.3A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. T...
CVE-2024-24860MEDIUM5.3A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can ...
CVE-2024-24859MEDIUM4.8A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can resu...
CVE-2024-24858MEDIUM5.3A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can...
CVE-2024-24857MEDIUM6.8A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. ...
CVE-2024-24855MEDIUM4.7A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can r...
CVE-2024-23196MEDIUM4.7A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can r...
CVE-2024-22667HIGH7.8Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the err...
CVE-2024-22386MEDIUM4.7A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. ...
CVE-2024-24865MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll ...
CVE-2024-24848MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MJS Software PT Si...
CVE-2024-24847MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgadbois Calculato...
CVE-2024-24846MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MightyThemes Might...
CVE-2024-24841MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan's Art Add Cust...
CVE-2024-24839MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Anto...
CVE-2024-24838MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now