2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23937MEDIUM4.3This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sili...
CVE-2024-23930MEDIUM4.3This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations o...
CVE-2024-23928MEDIUM6.5This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i...
CVE-2024-1211HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16...
CVE-2024-11611HIGH7.8AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability ...
CVE-2024-11610HIGH7.8AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability ...
CVE-2024-11609HIGH7.8AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...
CVE-2024-10604MEDIUM5.3Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, ...
CVE-2024-10603MEDIUM5.3Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be ...
CVE-2024-10026MEDIUM5.3A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate ...
CVE-2024-44142HIGH7.8The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously...
CVE-2024-12248CRITICAL9.8Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send spe...
CVE-2024-2658HIGH8.5A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configur...
CVE-2024-55417MEDIUM4.3DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user u...
CVE-2024-55416LOW3.5DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticate...
CVE-2024-55415MEDIUM5.7DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
CVE-2024-53615MEDIUM6.5A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through...
CVE-2024-8494MEDIUM6.5The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u...
CVE-2024-13742CRITICAL9.8The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versi...
CVE-2024-13720CRITICAL9.1The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida...
CVE-2024-13715MEDIUM4.3The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability che...
CVE-2024-13707HIGH8.1The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-13705MEDIUM6.1The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg wi...
CVE-2024-13700MEDIUM5.4The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortco...
CVE-2024-13671HIGH7.5The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now