2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39298MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix handling of dissolved but no...
CVE-2024-39296MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: bonding: fix oops during rmmod "rmmod bonding" cau...
CVE-2024-39293MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: Revert "xsk: Support redirect to any socket bound t...
CVE-2024-39276MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xa...
CVE-2024-38661MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: s390/ap: Fix crash in AP internal function modify_b...
CVE-2024-38385MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: genirq/irqdesc: Prevent use-after-free in irq_find_...
CVE-2024-38306MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: btrfs: protect folio::private when attaching extent...
CVE-2024-37354MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: btrfs: fix crash on racing fsync and size-extending...
CVE-2024-37087MEDIUM5.3The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server m...
CVE-2024-37086MEDIUM6.8VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a v...
CVE-2024-5451MEDIUM6.4The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-38951MEDIUM6.5A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink mes...
CVE-2024-32111MEDIUM5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress all...
CVE-2024-6302MEDIUM5.5Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to re...
CVE-2024-6300MEDIUM5.3Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were pre...
CVE-2024-4846MEDIUM6.3Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker ...
CVE-2024-31111MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ...
CVE-2024-28832MEDIUM4.8Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users...
CVE-2024-28831MEDIUM5.4Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute ...
CVE-2024-6307MEDIUM6.4WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to i...
CVE-2024-34142MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-34141MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-3249MEDIUM4.3The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2024-4759MEDIUM5.5The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with...
CVE-2024-32855MEDIUM4.4Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high pri...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now