2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9451MEDIUM6.4The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' para...
CVE-2024-9449MEDIUM6.4The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all version...
CVE-2024-39586MEDIUM4.3Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high ...
CVE-2024-39440MEDIUM4.4In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of ser...
CVE-2024-39439MEDIUM4.4In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o...
CVE-2024-39438MEDIUM6.7In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l...
CVE-2024-39437MEDIUM6.7In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l...
CVE-2024-39436MEDIUM6.7In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l...
CVE-2024-5968MEDIUM4.8The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery set...
CVE-2024-47191HIGH7.1pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context ...
CVE-2024-45160CRITICAL9.1Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 clien...
CVE-2024-42934MEDIUM5OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting ...
CVE-2024-32608CRITICAL9.8HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer a...
CVE-2024-45179HIGH7.2An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validatio...
CVE-2024-35288HIGH7.8Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because...
CVE-2024-25286Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2024-25285Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2024-25284Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2024-25283Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2024-25282Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and...
CVE-2024-7963MEDIUM6.4The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multi...
CVE-2024-9603HIGH8.8Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-9602HIGH8.8Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memo...
CVE-2024-9412HIGH8.4An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthor...
CVE-2024-36814MEDIUM4.9An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now