2024 CVE Vulnerabilities

39,233 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-21001MEDIUM5.4Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform...
CVE-2024-20998MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2024-20994MEDIUM5.3Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t...
CVE-2024-20993MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2024-20992MEDIUM4.4Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Content integration). The...
CVE-2024-20991MEDIUM5.3Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported v...
CVE-2024-20990MEDIUM5.3Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: Templates). Supporte...
CVE-2024-30378MEDIUM6.9A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authentic...
CVE-2024-32455MEDIUM4.3Missing Authorization vulnerability in Very Good Plugins Fatal Error Notify.This issue affects Fatal Error Notify: from ...
CVE-2024-3873MEDIUM4.3A vulnerability was found in SMI SMI-EX-5414W up to 1.0.03. It has been classified as problematic. This affects an unkno...
CVE-2024-3862MEDIUM5.3The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a...
CVE-2024-3861MEDIUM4If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and l...
CVE-2024-3860MEDIUM6.2An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently tra...
CVE-2024-3859MEDIUM5.9On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by...
CVE-2024-3855MEDIUM6.5In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability ...
CVE-2024-32024MEDIUM6.5Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.p...
CVE-2024-32023MEDIUM5.3Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.p...
CVE-2024-31451MEDIUM5.3DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.p...
CVE-2024-30256MEDIUM6.4Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forger...
CVE-2024-3869MEDIUM4.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ...
CVE-2024-3672MEDIUM5.4The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' sh...
CVE-2024-3243MEDIUM4.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing c...
CVE-2024-3367MEDIUM5.5Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to...
CVE-2024-3867MEDIUM6.1The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad...
CVE-2024-1357MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now