2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-3555HIGH7.2The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to un...
CVE-2024-2019HIGH7.5The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss...
CVE-2024-4870HIGH7.2The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to,...
CVE-2024-4540HIGH7.5A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to ...
CVE-2024-32983HIGH7.5Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSO...
CVE-2024-36128HIGH7.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numer...
CVE-2024-36127HIGH7.5apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in l...
CVE-2024-36728HIGH8.1TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows...
CVE-2024-36569HIGH8.1Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.
CVE-2024-35631HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision...
CVE-2024-35630HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdv...
CVE-2024-23670HIGH8.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,...
CVE-2024-23668HIGH8.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,...
CVE-2024-23667HIGH8.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,...
CVE-2024-23665HIGH8.8Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, ...
CVE-2024-23363HIGH7.5Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.
CVE-2024-23360HIGH7.8Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
CVE-2024-36963HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permission...
CVE-2024-36960HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled eve...
CVE-2024-20066HIGH7.5In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of ...
CVE-2024-5588HIGH8.8A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by ...
CVE-2024-36391HIGH7.4MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
CVE-2024-36390HIGH7.5MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service
CVE-2024-2178HIGH7.5A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' en...
CVE-2024-4148HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now