2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-36027HIGH7.1In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: do not flag ZEROOUT on non-dirty exte...
CVE-2024-35430HIGH8.1In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks whil...
CVE-2024-36019HIGH7.1In the Linux kernel, the following vulnerability has been resolved: regmap: maple: Fix cache corruption in regcache_map...
CVE-2024-3584HIGH7.5qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{n...
CVE-2024-5326HIGH8.8The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modi...
CVE-2024-5207HIGH7.2The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for W...
CVE-2024-36267HIGH8.1Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, ...
CVE-2024-36114HIGH8.6Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompr...
CVE-2024-35492HIGH7.5Cesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c....
CVE-2024-36016HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_rece...
CVE-2024-35434HIGH7.5Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/...
CVE-2024-36427HIGH8.1The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authent...
CVE-2024-35333HIGH8.4A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occ...
CVE-2024-36378HIGH7.5In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
CVE-2024-36377HIGH8.1In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
CVE-2024-36376HIGH8.1In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their p...
CVE-2024-36365HIGH8.1In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate...
CVE-2024-5185HIGH8.3The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result...
CVE-2024-25977HIGH7.3The application does not change the session token when using the login or logout functionality. An attacker can set a se...
CVE-2024-28826HIGH8.1Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and...
CVE-2024-36015HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In re...
CVE-2024-4611HIGH8.1The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_valu...
CVE-2024-21512HIGH8.2Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitizatio...
CVE-2024-5204HIGH8.8The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1...
CVE-2024-35226HIGH7.3Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now