2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6466MEDIUM5.3NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products ...
CVE-2024-13404MEDIUM6.1The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in al...
CVE-2024-12104HIGH7.5The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthori...
CVE-2024-12005MEDIUM6.1The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0...
CVE-2024-10936HIGH8.8The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6....
CVE-2024-13536MEDIUM5.3The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and incl...
CVE-2024-45091MEDIUM5.5IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensi...
CVE-2024-13454MEDIUM5.3Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the ...
CVE-2024-22349LOW3.3IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which c...
CVE-2024-22348HIGH7.5IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) whi...
CVE-2024-22347HIGH7.5IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algor...
CVE-2024-51738HIGH8.1Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementat...
CVE-2024-45647CRITICAL9.8IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow...
CVE-2024-13176MEDIUM4.1Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signat...
CVE-2024-13524MEDIUM4.5A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected ...
CVE-2024-41783CRITICAL9.1IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inje...
CVE-2024-41743HIGH7.5IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connect...
CVE-2024-41742HIGH7.5IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout...
CVE-2024-38337CRITICAL9.1IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker ...
CVE-2024-57929HIGH7.1In the Linux kernel, the following vulnerability has been resolved: dm array: fix releasing a faulty array block twice ...
CVE-2024-57928HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfs: Fix enomem handling in buffered reads If ne...
CVE-2024-57927MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfs: Fix oops in nfs_netfs_init_request() when copy...
CVE-2024-57926HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Set private->all_drm_private[i]->drm ...
CVE-2024-57925HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix a missing return value check bug In the...
CVE-2024-57924MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file hand...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now