2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-34063LOW2.5vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secre...
CVE-2024-32882LOW2.7Wagtail is an open source content management system built on Django. In affected versions if a model has been made avail...
CVE-2024-3471LOW3.4The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allo...
CVE-2024-26992LOW3.3In the Linux kernel, the following vulnerability has been resolved: KVM: x86/pmu: Disable support for adaptive PEBS Dr...
CVE-2024-4226LOW3.5It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all use...
CVE-2024-4327LOW3.5A vulnerability was found in Apryse WebViewer up to 10.8.0. It has been classified as problematic. This affects an unkno...
CVE-2024-31747LOW2.1An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximat...
CVE-2024-32268LOW3.3An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to ...
CVE-2024-3034LOW2.7The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13...
CVE-2024-3076LOW3.8The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation a...
CVE-2024-4198LOW2.7Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows ...
CVE-2024-4195LOW2.7Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows...
CVE-2024-32236LOW3.5An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in...
CVE-2024-23228LOW3.3This issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Note...
CVE-2024-2972LOW3.8The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button ...
CVE-2024-4063LOW3.7A vulnerability was found in EZVIZ CS-C6-21WFR-8 5.2.7 Build 170628. It has been classified as problematic. This affects...
CVE-2024-4062LOW3.7A vulnerability was found in Hualai Xiaofang iSC5 3.2.2_112 and classified as problematic. Affected by this issue is som...
CVE-2024-32482LOW2.2The Tillitis TKey signer device application is an ed25519 signing tool. A vulnerability has been found that makes it pos...
CVE-2024-3177LOW2.7A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable sec...
CVE-2024-32405LOW2.6Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via...
CVE-2024-29733LOW2.7Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate v...
CVE-2024-31991LOW3.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c...
CVE-2024-29963LOW3.8 Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't ...
CVE-2024-32325LOW2.4TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in ...
CVE-2024-28076LOW3.8The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now