2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-26470HIGH8.1A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v...
CVE-2024-26461HIGH7.5Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CVE-2024-26131HIGH7.8Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redire...
CVE-2024-25932HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows C...
CVE-2024-25931HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1....
CVE-2024-25930HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Cu...
CVE-2024-25832HIGH8.8F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to ...
CVE-2024-25713HIGH8.6yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function l...
CVE-2024-25262HIGH8.1texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulne...
CVE-2024-25006HIGH8.1XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to adm...
CVE-2024-24701HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-base...
CVE-2024-23519HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before ...
CVE-2024-23302HIGH7.5Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
CVE-2024-22939HIGH8.8Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the syst...
CVE-2024-20321HIGH8.6A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an una...
CVE-2024-20267HIGH8.6A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attack...
CVE-2024-1939HIGH8.8Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-1938HIGH8.8Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object cor...
CVE-2024-1928HIGH7.2A vulnerability, which was classified as critical, has been found in SourceCodester Web-Based Student Clearance System 1...
CVE-2024-1470HIGH7.8Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows all...
CVE-2024-1317HIGH8.8The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2024-1206HIGH8.8The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up t...
CVE-2024-0702HIGH7.3The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to miss...
CVE-2024-26146HIGH7.5Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer t...
CVE-2024-26141HIGH7.5Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now