2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45012MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: use dma non-coherent allocator C...
CVE-2024-45011MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing de...
CVE-2024-45010MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only mark 'subflow' endp as available A...
CVE-2024-45009MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ...
CVE-2024-44851MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to exe...
CVE-2024-41868MEDIUM5.5Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc...
CVE-2024-4465MEDIUM5An access control vulnerability was discovered in the Reports section due to a specific access restriction not being pro...
CVE-2024-43793MEDIUM6.4Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 o...
CVE-2024-8646MEDIUM6.1In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerab...
CVE-2024-5416MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-45789MEDIUM4.3This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API...
CVE-2024-45787MEDIUM6.5This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in...
CVE-2024-45786MEDIUM6.5This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints....
CVE-2024-8096MEDIUM6.5When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify tha...
CVE-2024-8045MEDIUM5.4The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag’ ...
CVE-2024-8440MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-7716MEDIUM4.8The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-3899MEDIUM4.8The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings...
CVE-2024-7727MEDIUM5.3The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of ...
CVE-2024-7721MEDIUM4.3The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modificati...
CVE-2024-39808MEDIUM4.6Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows ...
CVE-2024-24972MEDIUM6.5Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface...
CVE-2024-23906MEDIUM6.1Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnost...
CVE-2024-40659MEDIUM5.5In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore...
CVE-2024-40656MEDIUM5.5In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across user...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now