2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29971CRITICAL9.8Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.
CVE-2024-29970CRITICAL9.8Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals.
CVE-2024-25371HIGH7.5Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW si...
CVE-2024-57687CRITICAL9.8An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v...
CVE-2024-57686CRITICAL9.8A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record Sys...
CVE-2024-41787HIGH8.1IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security rest...
CVE-2024-57823MEDIUM5.5In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser...
CVE-2024-57822MEDIUM5.5In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads...
CVE-2024-13318MEDIUM5.3The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check...
CVE-2024-13183MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ paramet...
CVE-2024-12606MEDIUM4.3The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch...
CVE-2024-12473MEDIUM6.5The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch...
CVE-2024-56377MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject...
CVE-2024-56376MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users ...
CVE-2024-51229HIGH8.8Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via th...
CVE-2024-46464HIGH7.8In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated...
CVE-2024-55226MEDIUM5.4Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via th...
CVE-2024-55225CRITICAL9.8An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, inc...
CVE-2024-55224CRITICAL9.6An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting...
CVE-2024-48806MEDIUM6.8Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate pr...
CVE-2024-13312MEDIUM5.3Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from ...
CVE-2024-13311HIGH7.3Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file ...
CVE-2024-13310MEDIUM6.5Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*.
CVE-2024-13309MEDIUM5.4Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Se...
CVE-2024-13308LOW3.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Bac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now