2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11225MEDIUM6.1The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripti...
CVE-2024-10666MEDIUM4.3The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all ve...
CVE-2024-10034MEDIUM5.5The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga...
CVE-2024-38296MEDIUM4.4Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain ...
CVE-2024-47142MEDIUM5.5AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue wi...
CVE-2024-45837MEDIUM5.4Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A networ...
CVE-2024-39290MEDIUM6.5Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticate...
CVE-2024-52056MEDIUM6.5Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any...
CVE-2024-52055MEDIUM4.9Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any f...
CVE-2024-52616MEDIUM5.3A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementi...
CVE-2024-52615MEDIUM5.3A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies at...
CVE-2024-49588MEDIUM6.8Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.
CVE-2024-53094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SP...
CVE-2024-53093MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need t...
CVE-2024-53092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct i...
CVE-2024-53091MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has...
CVE-2024-53090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() c...
CVE-2024-53089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard inte...
CVE-2024-53333MEDIUM6.3TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. Th...
CVE-2024-52309MEDIUM5.1SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur...
CVE-2024-52307MEDIUM5.6authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ en...
CVE-2024-49529MEDIUM5.5InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2024-45517MEDIUM5.4An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h...
CVE-2024-45513MEDIUM4.8An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability ex...
CVE-2024-45194MEDIUM4.8In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Si...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now