2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43766 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th... |
| CVE-2024-50337 | MEDIUM | 5.3 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to... |
| CVE-2024-10938 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives ... |
| CVE-2024-56208 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in desertthemes NewsM... |
| CVE-2024-54222 | MEDIUM | 4.3 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Accelerator seraphinite-accelerator allows Retr... |
| CVE-2024-52387 | MEDIUM | 5.9 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste... |
| CVE-2024-51915 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo... |
| CVE-2024-50555 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento... |
| CVE-2024-50452 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Bl... |
| CVE-2024-43228 | MEDIUM | 5.3 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in SecuPress SecuPress Free secupress.This issue affects SecuPress Free: from n/a th... |
| CVE-2024-34438 | MEDIUM | 5.3 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a... |
| CVE-2024-31118 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configure... |
| CVE-2024-21961 | MEDIUM | 6 | 0.3% | Feb 13, 2026 | Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with acces... |
| CVE-2024-36319 | MEDIUM | 6.3 | 0.1% | Feb 12, 2026 | Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr... |
| CVE-2024-50618 | MEDIUM | 4.3 | 0.2% | Feb 11, 2026 | A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 all... |
| CVE-2024-26479 | MEDIUM | 5.3 | 0.5% | Feb 11, 2026 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command... |
| CVE-2024-26478 | MEDIUM | 5.3 | 0.4% | Feb 11, 2026 | An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/us... |
| CVE-2024-36316 | MEDIUM | 5.5 | 0.2% | Feb 11, 2026 | The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially ... |
| CVE-2024-56807 | MEDIUM | 5.5 | 0.1% | Feb 11, 2026 | An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local netwo... |
| CVE-2024-36311 | MEDIUM | 4.6 | 0.1% | Feb 10, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker t... |
| CVE-2024-36310 | MEDIUM | 4.6 | 0.2% | Feb 10, 2026 | Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds... |
| CVE-2024-21953 | MEDIUM | 5.9 | 0.2% | Feb 10, 2026 | Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss o... |
| CVE-2024-54192 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_g... |
| CVE-2024-52334 | MEDIUM | 6.3 | 0.3% | Feb 10, 2026 | A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not ... |
| CVE-2024-51451 | MEDIUM | 6.5 | 0.2% | Feb 4, 2026 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now