2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26647 | MEDIUM | 5.5 | 0.2% | Mar 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix late derefrence 'dsc' check in... |
| CVE-2024-26646 | MEDIUM | 5.5 | 0.2% | Mar 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for syst... |
| CVE-2024-1313 | MEDIUM | 6.5 | 0.6% | Mar 26, 2024 | It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a ... |
| CVE-2024-29735 | MEDIUM | 5.3 | 1.5% | Mar 26, 2024 | Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 throug... |
| CVE-2024-29833 | MEDIUM | 5.4 | 0.4% | Mar 26, 2024 | The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by usi... |
| CVE-2024-29832 | MEDIUM | 6.1 | 0.4% | Mar 26, 2024 | The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross S... |
| CVE-2024-29810 | MEDIUM | 5.4 | 0.4% | Mar 26, 2024 | The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross ... |
| CVE-2024-29809 | MEDIUM | 5.4 | 0.4% | Mar 26, 2024 | The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross ... |
| CVE-2024-29808 | MEDIUM | 5.4 | 0.4% | Mar 26, 2024 | The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross S... |
| CVE-2024-26645 | MEDIUM | 5.5 | 0.2% | Mar 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: tracing: Ensure visibility when inserting an elemen... |
| CVE-2024-26644 | MEDIUM | 5.5 | 0.2% | Mar 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to sn... |
| CVE-2024-25957 | MEDIUM | 5.5 | 0.2% | Mar 26, 2024 | Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in ... |
| CVE-2024-25956 | MEDIUM | 5.5 | 0.2% | Mar 26, 2024 | Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenti... |
| CVE-2024-29197 | MEDIUM | 6.5 | 0.7% | Mar 26, 2024 | Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true... |
| CVE-2024-22356 | MEDIUM | 4.9 | 0.5% | Mar 26, 2024 | IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 t... |
| CVE-2024-29883 | MEDIUM | 4.9 | 0.6% | Mar 26, 2024 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work... |
| CVE-2024-29881 | MEDIUM | 6.1 | 0.7% | Mar 26, 2024 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s cont... |
| CVE-2024-29203 | MEDIUM | 6.1 | 0.7% | Mar 26, 2024 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s conte... |
| CVE-2024-1455 | MEDIUM | 5.9 | 0.8% | Mar 26, 2024 | A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Enti... |
| CVE-2024-30233 | MEDIUM | 6.5 | 0.5% | Mar 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects... |
| CVE-2024-2906 | MEDIUM | 6.5 | 0.5% | Mar 26, 2024 | Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. |
| CVE-2024-22156 | MEDIUM | 6.5 | 0.4% | Mar 26, 2024 | Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15. |
| CVE-2024-30232 | MEDIUM | 5.4 | 0.3% | Mar 26, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons E... |
| CVE-2024-29644 | MEDIUM | 6.1 | 0.8% | Mar 26, 2024 | Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code v... |
| CVE-2024-24719 | MEDIUM | 4.3 | 0.3% | Mar 26, 2024 | Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Loca... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now