2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24870MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Ad...
CVE-2024-24866MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship:...
CVE-2024-20016MEDIUM4.4In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service w...
CVE-2024-20015HIGH7.8In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalati...
CVE-2024-20013MEDIUM6.7In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio...
CVE-2024-20012MEDIUM6.7In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of...
CVE-2024-20011CRITICAL9.8In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote ...
CVE-2024-20010MEDIUM6.7In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of...
CVE-2024-20009HIGH8.8In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote e...
CVE-2024-20007HIGH7.5In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of...
CVE-2024-20006MEDIUM6.7In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri...
CVE-2024-20004HIGH7.5In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of ...
CVE-2024-20003HIGH7.5In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of ...
CVE-2024-20002MEDIUM6.7In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ...
CVE-2024-20001MEDIUM6.7In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ...
CVE-2024-25089CRITICAL9.8Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC...
CVE-2024-25062HIGH7.5An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD ...
CVE-2024-1215MEDIUM6.1A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by ...
CVE-2024-0853MEDIUM5.3curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) te...
CVE-2024-1064HIGH7.5A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticate...
CVE-2024-23550MEDIUM5.5HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
CVE-2024-0909HIGH7.5The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and...
CVE-2024-0895MEDIUM5.4The PDF Flipbook, 3D Flipbook – DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline s...
CVE-2024-1200MEDIUM6.5A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functi...
CVE-2024-1199HIGH7.5A vulnerability has been found in CodeAstro Employee Task Management System 1.0 and classified as problematic. Affected ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now