2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0836MEDIUM4.3The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-22236MEDIUM5.5In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1....
CVE-2024-0914MEDIUM5.9A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 pad...
CVE-2024-1069HIGH7.2The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio...
CVE-2024-23745CRITICAL9.8In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to exec...
CVE-2024-22569MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a craft...
CVE-2024-23834MEDIUM6.1Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in s...
CVE-2024-1077HIGH8.8Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap...
CVE-2024-1060HIGH8.8Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap ...
CVE-2024-1059HIGH8.8Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially expl...
CVE-2024-24567MEDIUM5.3Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in b...
CVE-2024-24558MEDIUM6.1TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tans...
CVE-2024-24556MEDIUM6.1urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable t...
CVE-2024-23841MEDIUM6.1apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nex...
CVE-2024-21388MEDIUM6.5Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2024-1036CRITICAL9.8A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon o...
CVE-2024-24565MEDIUM6.5CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. Th...
CVE-2024-23840MEDIUM5.5GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a ta...
CVE-2024-23838HIGH7.5TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain con...
CVE-2024-23825MEDIUM4.9TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL...
CVE-2024-23647HIGH8.8Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to c...
CVE-2024-22200MEDIUM5.3vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate...
CVE-2024-22193MEDIUM4.3The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul...
CVE-2024-21671LOW3.7The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul...
CVE-2024-21653CRITICAL9.8The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now