2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57933MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gve: guard XSK operations on the existence of queue...
CVE-2024-57932MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gve: guard XDP xmit NDO on existence of xdp queues ...
CVE-2024-57931MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: selinux: ignore unknown extended permissions When ...
CVE-2024-57930MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing: Have process_string() also allow arrays I...
CVE-2024-52973MEDIUM6.5An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted requ...
CVE-2024-43709HIGH7.5An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resul...
CVE-2024-37284MEDIUM5.5Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to scan a file or process...
CVE-2024-13444MEDIUM6.1The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2....
CVE-2024-13230MEDIUM5.3The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limit...
CVE-2024-11226MEDIUM6.4The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' param...
CVE-2024-6466MEDIUM5.3NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products ...
CVE-2024-13404MEDIUM6.1The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in al...
CVE-2024-12104HIGH7.5The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthori...
CVE-2024-12005MEDIUM6.1The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0...
CVE-2024-10936HIGH8.8The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6....
CVE-2024-13536MEDIUM5.3The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and incl...
CVE-2024-45091MEDIUM5.5IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensi...
CVE-2024-13454MEDIUM5.3Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the ...
CVE-2024-22349LOW3.3IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which c...
CVE-2024-22348HIGH7.5IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) whi...
CVE-2024-22347HIGH7.5IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algor...
CVE-2024-51738HIGH8.1Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementat...
CVE-2024-45647CRITICAL9.8IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow...
CVE-2024-13176MEDIUM4.1Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signat...
CVE-2024-13524MEDIUM4.5A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now