2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20996MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2024-6777MEDIUM6.5Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to instal...
CVE-2024-6395MEDIUM5.3An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the ...
CVE-2024-6336MEDIUM5.3A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauth...
CVE-2024-5817MEDIUM6.5An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue co...
CVE-2024-5816MEDIUM5.3An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App ...
CVE-2024-5815MEDIUM6.5A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned reposi...
CVE-2024-5795MEDIUM6.5A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded...
CVE-2024-5566MEDIUM6.5An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate ...
CVE-2024-40536MEDIUM5.3Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 were discovered to contain a stack overflow via the pin_3g_code ...
CVE-2024-40503MEDIUM6.5An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functiona...
CVE-2024-39036MEDIUM6.5SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
CVE-2024-39908MEDIUM4.3 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that ha...
CVE-2024-6326MEDIUM5.5An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A mali...
CVE-2024-6325MEDIUM6.5The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/e...
CVE-2024-40626MEDIUM5.4Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering pr...
CVE-2024-3232MEDIUM6.8A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with admini...
CVE-2024-6621MEDIUM4.3The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauth...
CVE-2024-6579MEDIUM4.3The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings m...
CVE-2024-6570MEDIUM5.3The Glossary plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.26. Th...
CVE-2024-6565MEDIUM5.3The AForms — Form Builder for Price Calculator & Cost Estimation plugin for WordPress is vulnerable to Full Path Disclos...
CVE-2024-5852MEDIUM4.3The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including...
CVE-2024-3779MEDIUM5.5Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker t...
CVE-2024-3587MEDIUM5.4The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-2691MEDIUM5.4The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now