2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45198HIGH8.8insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters i...
CVE-2024-22611CRITICAL9.8OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.cl...
CVE-2024-4877HIGH8.8OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi...
CVE-2024-9416MEDIUM5.4The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc...
CVE-2024-53868HIGH7.5Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffi...
CVE-2024-13673MEDIUM6.4The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' s...
CVE-2024-38392CRITICAL9.1Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remo...
CVE-2024-37917HIGH7.5Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (so...
CVE-2024-36337HIGH7.9Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss ...
CVE-2024-36336HIGH7.9Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a...
CVE-2024-36328HIGH7.3Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss ...
CVE-2024-56476MEDIUM5.3IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login a...
CVE-2024-56475MEDIUM5.4IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authent...
CVE-2024-56474HIGH8.8IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker t...
CVE-2024-56341MEDIUM5.4IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an auth...
CVE-2024-25051HIGH7.2IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated p...
CVE-2024-50597HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50596HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50595HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50594HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50385HIGH7.5A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-50384HIGH7.5A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-45064CRITICAL9.8A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-13637MEDIUM6.5The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2024-12410MEDIUM4.9The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now