2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38545HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix UAF for cq async event The refcount ...
CVE-2024-38542HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: boundary check before installing cq c...
CVE-2024-38541HIGH7.8In the Linux kernel, the following vulnerability has been resolved: of: module: add buffer overflow check in of_modalia...
CVE-2024-38538HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth h...
CVE-2024-38329HIGH7.7IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote a...
CVE-2024-36979HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix vlan use-after-free syzbot r...
CVE-2024-35780HIGH8.5Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Pag...
CVE-2024-36978HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in m...
CVE-2024-6132HIGH8.8The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2024-5853HIGH8.8The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2024-5574HIGH7.5The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu...
CVE-2024-5343HIGH8.8The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2024-5724HIGH8.8The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc...
CVE-2024-5649HIGH8.8The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1....
CVE-2024-2381HIGH8.8The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missin...
CVE-2024-6125HIGH8.1The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and in...
CVE-2024-6146HIGH8.8Actiontec WCB6200Q uh_get_postdata_withupload Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...
CVE-2024-6145HIGH8.8Actiontec WCB6200Q Cookie Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent ...
CVE-2024-6144HIGH8.8Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2024-6143HIGH8.8Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows net...
CVE-2024-6142HIGH8.8Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ne...
CVE-2024-38276HIGH8.8Incorrect CSRF token checks resulted in multiple CSRF risks.
CVE-2024-38275HIGH7.5The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header ...
CVE-2024-37821HIGH8.8An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attacker...
CVE-2024-36974HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now