2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52392MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in w3speedster W3SPEEDSTER w3speedster-wp.This issue affects W3SPEEDSTER...
CVE-2024-51669HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Wi...
CVE-2024-30424MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Beaver Buil...
CVE-2024-11400MEDIUM6.1The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri...
CVE-2024-52763MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows ...
CVE-2024-52762MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows atta...
CVE-2024-52360CRITICAL9.8IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send speci...
CVE-2024-52359HIGH8.8IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions ...
CVE-2024-45422HIGH7.5Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial o...
CVE-2024-45420MEDIUM6.5Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a de...
CVE-2024-45419HIGH7.5Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via...
CVE-2024-37070MEDIUM6.5IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information ...
CVE-2024-1271Rejected reason: This CVE was previously published at https://bugzilla.redhat.com/show_bug.cgi?id=2262978 but later reje...
CVE-2024-11395HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-52759CRITICAL9.8D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp funct...
CVE-2024-52714CRITICAL9.8Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
CVE-2024-51503HIGH8.8A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an at...
CVE-2024-50430MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Bea...
CVE-2024-48694CRITICAL9.8File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote att...
CVE-2024-21697HIGH8.8This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and ...
CVE-2024-53088MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: i40e: fix race condition by adding filter's interme...
CVE-2024-53087MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix possible exec queue leak in exec IOCTL ...
CVE-2024-53086MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe: Drop VM dma-resv lock on xe_sync_in_fence_g...
CVE-2024-53085MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tpm: Lock TPM chip in tpm_pm_suspend() first Setti...
CVE-2024-53084MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Break an object reference loop Wh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now