2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39434MEDIUM4.4In drm service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of...
CVE-2024-39433MEDIUM4.4In drm service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o...
CVE-2024-39432MEDIUM4.5In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote deni...
CVE-2024-39431MEDIUM4.5In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote den...
CVE-2024-9049MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-9029HIGH7.5A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read...
CVE-2024-8991MEDIUM5.4The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and o...
CVE-2024-8681MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Medi...
CVE-2024-7400HIGH8.5The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file...
CVE-2024-9130HIGH7.2The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via...
CVE-2024-8965MEDIUM5.4The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom ...
CVE-2024-8922HIGH8.8The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Inject...
CVE-2024-7714HIGH7.5The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls ...
CVE-2024-7713HIGH7.5The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, al...
CVE-2024-7011MEDIUM6.5Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, ...
CVE-2024-8974MEDIUM4.3Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 ...
CVE-2024-4099MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to ...
CVE-2024-47177Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-47076, CVE-2024-47175, CVE-2024-471...
CVE-2024-47176MEDIUM5.3CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality inclu...
CVE-2024-47175CRITICAL9.8CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libpp...
CVE-2024-47076HIGH8.6CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for...
CVE-2024-40508HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40507HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40506HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-6769HIGH8.4A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Win...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now