2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23502MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in InfornWeb Posts Li...
CVE-2024-0833HIGH7.8In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the ...
CVE-2024-0832HIGH7.8In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applicati...
CVE-2024-0219HIGH7.8In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the appli...
CVE-2024-1103MEDIUM5.4A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by ...
CVE-2024-22140HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro...
CVE-2024-22136HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in DroitThemes Droit Elementor Addons – Widgets, Blocks, Templates Libra...
CVE-2024-1112CRITICAL9.8Heap-based buffer overflow vulnerability in Resource Hacker, developed by Angus Johnson, affecting version 3.6.0.92. Thi...
CVE-2024-22304HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Borbis Media FreshMail For WordPress.This issue affects FreshMail For...
CVE-2024-22291HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Col...
CVE-2024-22285HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Elise Bosse Frontpage Manager.This issue affects Frontpage Manager: f...
CVE-2024-22143HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9....
CVE-2024-1087Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of ...
CVE-2024-1086HIGH7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2024-1085HIGH7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2024-0589MEDIUM5.4Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and e...
CVE-2024-23507HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Co...
CVE-2024-22305HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for Wo...
CVE-2024-22290HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Sc...
CVE-2024-22287MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS)....
CVE-2024-1099MEDIUM5.4A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFil...
CVE-2024-1098HIGH7.5A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuClo...
CVE-2024-23775HIGH7.5Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of...
CVE-2024-23170MEDIUM5.5An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA priva...
CVE-2024-1012CRITICAL9.8A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unkn...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now