2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33582HIGH7.8A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code wi...
CVE-2024-33581HIGH7.8A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker t...
CVE-2024-33580HIGH7.8A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with ...
CVE-2024-33579HIGH7.8A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevate...
CVE-2024-33578HIGH7.8A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated ...
CVE-2024-9869Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-8755CRITICAL9.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This ...
CVE-2024-47875MEDIUM6.1DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to n...
CVE-2024-47830MEDIUM5.8Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostn...
CVE-2024-47074CRITICAL9.8DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source ...
CVE-2024-45403HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3...
CVE-2024-45402CRITICAL9.8Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsi...
CVE-2024-45397HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top...
CVE-2024-45396HIGH7.5Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attac...
CVE-2024-25622MEDIUM4.3h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers...
CVE-2024-9002HIGH7.8CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit...
CVE-2024-8531HIGH7.2CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Exp...
CVE-2024-8530MEDIUM5.9CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data whe...
CVE-2024-6657MEDIUM6.5A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuo...
CVE-2024-9856MEDIUM4.8A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this ...
CVE-2024-9855HIGH7.2A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this ...
CVE-2024-9707CRITICAL9.8The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca...
CVE-2024-9616MEDIUM6.1The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...
CVE-2024-9611MEDIUM6.1The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-9610MEDIUM6.1The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now