2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7256HIGH8.8Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to exe...
CVE-2024-7255HIGH8.8Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perf...
CVE-2024-6990HIGH8.8Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially pe...
CVE-2024-6873HIGH8.1It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector b...
CVE-2024-6242HIGH7.3A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot f...
CVE-2024-6040HIGH8.8In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multi...
CVE-2024-41265HIGH7.5A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via t...
CVE-2024-41264HIGH7.5An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostK...
CVE-2024-41260HIGH7.5A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allo...
CVE-2024-41946HIGH7.5REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity...
CVE-2024-41144HIGH7.1Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced post...
CVE-2024-41123HIGH7.5REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has...
CVE-2024-39832HIGH8.7Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error h...
CVE-2024-7358HIGH8.5A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected b...
CVE-2024-28972HIGH7.5Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthentica...
CVE-2024-6529HIGH7.1The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting ...
CVE-2024-3983HIGH8.1The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which cou...
CVE-2024-7338HIGH8.8A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the...
CVE-2024-6698HIGH8.8The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. T...
CVE-2024-7337HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by...
CVE-2024-7336HIGH8.8A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability...
CVE-2024-7335HIGH8.8A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function ...
CVE-2024-7334HIGH8.8A vulnerability was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. It has been rated as critical. This issue affects t...
CVE-2024-7333HIGH8.8A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability...
CVE-2024-6687HIGH7.5The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions u...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now