2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-26647MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix late derefrence 'dsc' check in...
CVE-2024-26646MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for syst...
CVE-2024-1313MEDIUM6.5It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a ...
CVE-2024-29735MEDIUM5.3Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 throug...
CVE-2024-29833MEDIUM5.4The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by usi...
CVE-2024-29832MEDIUM6.1The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross S...
CVE-2024-29810MEDIUM5.4The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross ...
CVE-2024-29809MEDIUM5.4The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross ...
CVE-2024-29808MEDIUM5.4The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross S...
CVE-2024-26645MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing: Ensure visibility when inserting an elemen...
CVE-2024-26644MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to sn...
CVE-2024-25957MEDIUM5.5Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in ...
CVE-2024-25956MEDIUM5.5Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenti...
CVE-2024-29197MEDIUM6.5Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true...
CVE-2024-22356MEDIUM4.9IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 t...
CVE-2024-29883MEDIUM4.9CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work...
CVE-2024-29881MEDIUM6.1TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s cont...
CVE-2024-29203MEDIUM6.1TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s conte...
CVE-2024-1455MEDIUM5.9A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Enti...
CVE-2024-30233MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects...
CVE-2024-2906MEDIUM6.5Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
CVE-2024-22156MEDIUM6.5Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.
CVE-2024-30232MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons E...
CVE-2024-29644MEDIUM6.1Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code v...
CVE-2024-24719MEDIUM4.3Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Loca...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now