2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-0107HIGH7.8NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use...
CVE-2024-0101HIGH7.5NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter ...
CVE-2024-42356HIGH7.2Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into a...
CVE-2024-41942HIGH7.2JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and ...
CVE-2024-7348HIGH7.5Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary...
CVE-2024-3659HIGH7.2Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sen...
CVE-2024-3035HIGH8.1A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior t...
CVE-2024-2800HIGH7.5ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 pri...
CVE-2024-6329HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 pr...
CVE-2024-42038HIGH7.8Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerabilit...
CVE-2024-42036HIGH7.5Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability...
CVE-2024-42035HIGH7.8Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may a...
CVE-2024-42033HIGH7.1Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability wi...
CVE-2024-42257HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: use memtostr_pad() for s_volume_name As with...
CVE-2024-42031HIGH7.5Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerabili...
CVE-2024-22069HIGH8.8There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissi...
CVE-2024-7150HIGH8.8The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id...
CVE-2024-6869HIGH7.1The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2024-7492HIGH8.8The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-7561HIGH8.8The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via d...
CVE-2024-7560HIGH7.2The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via...
CVE-2024-7486HIGH8.8The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 v...
CVE-2024-38202HIGH7.3Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabli...
CVE-2024-6893HIGH7.5The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This all...
CVE-2024-6891HIGH8.8Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now