2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6411HIGH8.8The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in al...
CVE-2024-39614HIGH7.5An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject t...
CVE-2024-38875HIGH7.5An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a poten...
CVE-2024-21526HIGH7.5All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to t...
CVE-2024-21525HIGH8.3All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the...
CVE-2024-21523HIGH7.5All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to ...
CVE-2024-21522HIGH7.5All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to th...
CVE-2024-21521HIGH7.5All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object w...
CVE-2024-38301HIGH7.8Dell Alienware Command Center, version 5.7.3.0 and prior, contains an improper access control vulnerability. A low privi...
CVE-2024-5792HIGH8.8The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all...
CVE-2024-6433HIGH7.5The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files...
CVE-2024-32670HIGH7Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes ...
CVE-2024-21417HIGH8.8Windows Text Services Framework Elevation of Privilege Vulnerability
CVE-2024-39883HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-...
CVE-2024-39882HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of a...
CVE-2024-39881HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption cond...
CVE-2024-39880HIGH8.8Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-...
CVE-2024-39069HIGH7.8An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hij...
CVE-2024-36676HIGH7.5Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targ...
CVE-2024-35154HIGH7.2IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to t...
CVE-2024-37829HIGH8.8An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafte...
CVE-2024-34726HIGH7.8In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This co...
CVE-2024-34725HIGH7In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. Thi...
CVE-2024-34724HIGH7In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead...
CVE-2024-34723HIGH7.8In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from back...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now