2024 CVE Vulnerabilities

39,152 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-3471LOW3.4The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allo...
CVE-2024-26992LOW3.3In the Linux kernel, the following vulnerability has been resolved: KVM: x86/pmu: Disable support for adaptive PEBS Dr...
CVE-2024-4226LOW3.5It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all use...
CVE-2024-4327LOW3.5A vulnerability was found in Apryse WebViewer up to 10.8.0. It has been classified as problematic. This affects an unkno...
CVE-2024-31747LOW2.1An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximat...
CVE-2024-32268LOW3.3An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to ...
CVE-2024-3034LOW2.7The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13...
CVE-2024-3076LOW3.8The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation a...
CVE-2024-4198LOW2.7Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows ...
CVE-2024-4195LOW2.7Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows...
CVE-2024-32236LOW3.5An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in...
CVE-2024-23228LOW3.3This issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Note...
CVE-2024-2972LOW3.8The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button ...
CVE-2024-4063LOW3.7A vulnerability was found in EZVIZ CS-C6-21WFR-8 5.2.7 Build 170628. It has been classified as problematic. This affects...
CVE-2024-4062LOW3.7A vulnerability was found in Hualai Xiaofang iSC5 3.2.2_112 and classified as problematic. Affected by this issue is som...
CVE-2024-32482LOW2.2The Tillitis TKey signer device application is an ed25519 signing tool. A vulnerability has been found that makes it pos...
CVE-2024-3177LOW2.7A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable sec...
CVE-2024-32405LOW2.6Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via...
CVE-2024-29733LOW2.7Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate v...
CVE-2024-31991LOW3.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c...
CVE-2024-29963LOW3.8 Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't ...
CVE-2024-32325LOW2.4TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in ...
CVE-2024-28076LOW3.8The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect...
CVE-2024-3932LOW1.3A vulnerability classified as problematic has been found in Totara LMS up to 18.7. This affects an unknown part of the c...
CVE-2024-3931LOW2A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unk...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now