2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6783MEDIUM4.8A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker...
CVE-2024-41836MEDIUM5.5InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that cou...
CVE-2024-34128MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-41012MEDIUM6.3In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close ra...
CVE-2024-6231MEDIUM5.9The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-4260MEDIUM6.5The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts vi...
CVE-2024-1575MEDIUM6.5The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions ...
CVE-2024-24507MEDIUM6.1Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser par...
CVE-2024-6638MEDIUM5.5An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an i...
CVE-2024-6122MEDIUM5.5An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may r...
CVE-2024-41880MEDIUM5.3In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effective...
CVE-2024-40075MEDIUM4.3Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.
CVE-2024-37380MEDIUM5.3A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+...
CVE-2024-41130MEDIUM6.5llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_fr...
CVE-2024-39688MEDIUM6.5Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated wi...
CVE-2024-41828MEDIUM6.5In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
CVE-2024-41826MEDIUM4.8In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
CVE-2024-41825MEDIUM5.4In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
CVE-2024-41824MEDIUM6.5In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific ca...
CVE-2024-41129MEDIUM4.4The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that o...
CVE-2024-32152MEDIUM4.3A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted maliciou...
CVE-2024-29073MEDIUM6.5An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe comm...
CVE-2024-41315MEDIUM6.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41314MEDIUM6.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface paramete...
CVE-2024-39902MEDIUM4.3Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Communi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now