2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1937MEDIUM6.5The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-41008MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: change vm->task_info handling This pat...
CVE-2024-6559MEDIUM5.3The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path ...
CVE-2024-4780MEDIUM6.4The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eih...
CVE-2024-6557MEDIUM5.3The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Pos...
CVE-2024-4224MEDIUM5.4An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V...
CVE-2024-40630MEDIUM4.3OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2024-40627MEDIUM5.8Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by ...
CVE-2024-39918MEDIUM4.3@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an...
CVE-2024-39912MEDIUM5.3web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that ...
CVE-2024-38360MEDIUM4.9Discourse is an open source platform for community discussion. In affected versions by creating replacement words with a...
CVE-2024-37386MEDIUM4.2An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Cert...
CVE-2024-31946MEDIUM4.2An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through ...
CVE-2024-39827MEDIUM5.5Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an...
CVE-2024-39826MEDIUM6.8Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct...
CVE-2024-39821MEDIUM4.4Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authentic...
CVE-2024-39820MEDIUM5Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may all...
CVE-2024-37016MEDIUM6.8Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.
CVE-2024-27238MEDIUM6.3Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated ...
CVE-2024-40555MEDIUM5.3Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.
CVE-2024-40553MEDIUM4.9Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.
CVE-2024-38496MEDIUM5.1The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group...
CVE-2024-38495MEDIUM5.3A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.
CVE-2024-38493MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convi...
CVE-2024-36458MEDIUM5.1The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now