2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-29121HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firassaidi WooComm...
CVE-2024-29116HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IconicWP WooThumbs...
CVE-2024-29110HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pauple Table & Con...
CVE-2024-29142HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebberZone Better ...
CVE-2024-29139HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Tilly MyCurat...
CVE-2024-29136HIGH8.8Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through...
CVE-2024-29135HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: fr...
CVE-2024-2635HIGH7.3 The configuration pages available are not intended to be placed on an Internet facing web server, as they expose file p...
CVE-2024-2632HIGH7.5A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot o...
CVE-2024-2614HIGH8.8Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence ...
CVE-2024-2613HIGH7.5Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption a...
CVE-2024-2612HIGH8.1If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or po...
CVE-2024-2608HIGH8.4`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experience...
CVE-2024-2607HIGH8.1Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue onl...
CVE-2024-24042HIGH8.8Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary ...
CVE-2024-26369HIGH7.5An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal a...
CVE-2024-22017HIGH7.3setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows th...
CVE-2024-28865HIGH7.5django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciou...
CVE-2024-28248HIGH7.2Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 an...
CVE-2024-21661HIGH7.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, a...
CVE-2024-0858HIGH8.8The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to ...
CVE-2024-0780HIGH8.8The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when reset...
CVE-2024-0779HIGH8.8The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF i...
CVE-2024-20761HIGH7.8Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbi...
CVE-2024-20754HIGH7.8Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now