2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38547MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: atomisp: ssh_css: Fix a null-pointer derefer...
CVE-2024-38546MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm: vc4: Fix possible null pointer dereference In...
CVE-2024-38544MEDIUM6.3In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt In r...
CVE-2024-38543MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm.c: handle src_pfns and dst_pfns alloca...
CVE-2024-38540MEDIUM4.4In the Linux kernel, the following vulnerability has been resolved: bnxt_re: avoid shift undefined behavior in bnxt_qpl...
CVE-2024-38539MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix kmemleak in rdma_core observed during...
CVE-2024-23443MEDIUM4.9A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a...
CVE-2024-35765MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Gree...
CVE-2024-5676MEDIUM6.8The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a...
CVE-2024-4632MEDIUM6.4The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for WordPr...
CVE-2024-0383MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-inst...
CVE-2024-0789MEDIUM5.3The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9...
CVE-2024-3894MEDIUM6.4The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-37881MEDIUM5.3SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measu...
CVE-2024-37387MEDIUM4Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited,...
CVE-2024-36252MEDIUM6.3Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3....
CVE-2024-1407MEDIUM5.4The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2024-5208MEDIUM6.5An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. T...
CVE-2024-35298MEDIUM4.3Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 all...
CVE-2024-5768MEDIUM6.4The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-4873MEDIUM4.3The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl...
CVE-2024-4787MEDIUM5.8The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, ...
CVE-2024-4663MEDIUM6.4The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ param...
CVE-2024-4623MEDIUM6.4The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘p...
CVE-2024-4541MEDIUM4.3The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now