2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-57892HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix slab-use-after-free due to dangling poin...
CVE-2024-57887HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm: adv7511: Fix use-after-free in adv7533_attach_...
CVE-2024-57857HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Remove direct link to net_device Do not ...
CVE-2024-57801HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Skip restore TC rules for vport rep with...
CVE-2024-57795HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Remove the direct link to net_device The...
CVE-2024-11848HIGH8.1The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-13351HIGH7.2The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-4227HIGH7.5In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forc...
CVE-2024-55577HIGH7Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file wh...
CVE-2024-57767HIGH8.6MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.
CVE-2024-57765HIGH7.5MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.
CVE-2024-57762HIGH7.5MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
CVE-2024-57761HIGH8.1An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execut...
CVE-2024-57757HIGH7.5JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.c...
CVE-2024-54730HIGH7.5Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.
CVE-2024-42911HIGH7.4ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vuln...
CVE-2024-50858HIGH8.8Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actio...
CVE-2024-55924HIGH8TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55921HIGH8.8TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-53263HIGH8.5Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it ...
CVE-2024-48858HIGH7.5Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated att...
CVE-2024-56374HIGH7.5An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit ...
CVE-2024-52006HIGH7.5Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2024-50338HIGH7.4Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS, and Linux. The...
CVE-2024-48857HIGH7.5NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated atta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now