2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57986MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix assumption that Resolution Multiplie...
CVE-2024-57985MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Cleanup global '__scm' on prob...
CVE-2024-57981MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix NULL pointer dereference on certain ...
CVE-2024-57978MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Fix potential error pointer derefe...
CVE-2024-57977MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: memcg: fix soft lockup in the OOM process A soft l...
CVE-2024-57976MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: do proper folio cleanup when cow_file_range(...
CVE-2024-57975MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: do proper folio cleanup when run_delalloc_no...
CVE-2024-57974MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: udp: Deal with race between UDP socket address chan...
CVE-2024-57973MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 3...
CVE-2024-57953MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rtc: tps6594: Fix integer overflow on 32bit systems...
CVE-2024-57423MEDIUM6.1A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary co...
CVE-2024-50684MEDIUM6.5SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient ...
CVE-2024-46226MEDIUM4.8A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary Jav...
CVE-2024-52925MEDIUM6.8In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unl...
CVE-2024-6810MEDIUM4.4The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin...
CVE-2024-13803MEDIUM5.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2024-13678MEDIUM6.1The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13669MEDIUM6.1The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13634MEDIUM6.1The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13630MEDIUM6.1The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13629MEDIUM6.1The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-13628MEDIUM6.1The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-13560MEDIUM4.3The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2024-13113MEDIUM5.9The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when output...
CVE-2024-12737MEDIUM6.1The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a pa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now