2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13521MEDIUM5.4The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2024-13509MEDIUM6.1The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in al...
CVE-2024-13448CRITICAL9.8The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2024-12807MEDIUM4.8The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could...
CVE-2024-12723MEDIUM6.1The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-11135HIGH7.5The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees'...
CVE-2024-53881MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm...
CVE-2024-53869MEDIUM5.5NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A suc...
CVE-2024-0150HIGH7.1NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before th...
CVE-2024-0149LOW3.3NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files....
CVE-2024-0147MEDIUM5.5NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been free...
CVE-2024-0146HIGH7.8NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory cor...
CVE-2024-0140MEDIUM6.8NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data is...
CVE-2024-0137MEDIUM6.5NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le...
CVE-2024-0136HIGH8.4NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le...
CVE-2024-0135HIGH7.6NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le...
CVE-2024-45341MEDIUM6.1A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that appl...
CVE-2024-45340HIGH8.8Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server...
CVE-2024-45339HIGH7.1When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged pr...
CVE-2024-45336MEDIUM6.1The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ contai...
CVE-2024-22315MEDIUM6.5IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker w...
CVE-2024-27263MEDIUM5.3IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obt...
CVE-2024-12649CRITICAL9.8Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow...
CVE-2024-12648CRITICAL9.8Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may ...
CVE-2024-12647CRITICAL9.8Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now