2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4376MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fanc...
CVE-2024-4205MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa...
CVE-2024-23847MEDIUM5.9Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co...
CVE-2024-5418MEDIUM5.4The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribu...
CVE-2024-1298MEDIUM6EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 ...
CVE-2024-35189MEDIUM6.5Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `Conne...
CVE-2024-32877MEDIUM4.7Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a...
CVE-2024-35228MEDIUM5.5Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in th...
CVE-2024-35468MEDIUM5.4A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers ...
CVE-2024-36118MEDIUM4.3MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions ca...
CVE-2024-35429MEDIUM6.5ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
CVE-2024-35352MEDIUM6.1A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentifie...
CVE-2024-35351MEDIUM5.4A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentifie...
CVE-2024-36959MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_d...
CVE-2024-36958MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure tha...
CVE-2024-36957MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: avoid off-by-one read from userspace ...
CVE-2024-36956MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Free all thermal zone debug memory...
CVE-2024-36954MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __...
CVE-2024-36953MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgi...
CVE-2024-36952MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Move NPIV's transport unregistration to...
CVE-2024-36951MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: range check cp bad op exception interru...
CVE-2024-36950MEDIUM4.4In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: mask bus reset interrupts between I...
CVE-2024-36949MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: sync all devices to wait all processes ...
CVE-2024-36948MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/xe_migrate: Cast to output precision before ...
CVE-2024-36947MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: qibfs: fix dentry leak simple_recursive_removal() ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now