2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39478MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA te...
CVE-2024-39477MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon EN...
CVE-2024-39476MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix deadlock that raid5d() wait for itsel...
CVE-2024-39475MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Handle err return when savagefb_chec...
CVE-2024-39474MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if ca...
CVE-2024-39473MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of...
CVE-2024-39472MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the leg...
CVE-2024-34481MEDIUM6.1drupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page.
CVE-2024-32498MEDIUM6.5An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file...
CVE-2024-39936MEDIUM5.9An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x th...
CVE-2024-6511MEDIUM6.1A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is th...
CVE-2024-37474MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: f...
CVE-2024-37472MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice ...
CVE-2024-37471MEDIUM6.1Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core:...
CVE-2024-37476MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack ...
CVE-2024-39929MEDIUM5.4Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filenam...
CVE-2024-22277MEDIUM5.4VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to ...
CVE-2024-39211MEDIUM5.3Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response ...
CVE-2024-6434MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in a...
CVE-2024-39884MEDIUM6.2A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of...
CVE-2024-1574MEDIUM6.7Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in the licensing featur...
CVE-2024-1573MEDIUM5.9Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENES...
CVE-2024-5641MEDIUM5.4The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2024-3639MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pos...
CVE-2024-3638MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marq...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now