2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8897MEDIUM6.1Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a t...
CVE-2024-7873CRITICAL9.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi...
CVE-2024-46362HIGH8.8FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana...
CVE-2024-46085HIGH8.8FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana...
CVE-2024-5998HIGH7.8A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization...
CVE-2024-8767CRITICAL9.9Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected...
CVE-2024-8761MEDIUM6.1The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. Thi...
CVE-2024-8490MEDIUM6.5The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-8093MEDIUM6.5The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which cou...
CVE-2024-8092MEDIUM5.4The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-8091MEDIUM6.5The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, whi...
CVE-2024-8052MEDIUM6.1The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as ...
CVE-2024-8051MEDIUM5.4The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-8047MEDIUM6.5The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which...
CVE-2024-8044MEDIUM6.5The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which...
CVE-2024-8043MEDIUM5.4The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-5170MEDIUM4.8The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which c...
CVE-2024-8110HIGH7.5Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer. If a computer on which the...
CVE-2024-7387CRITICAL9.1A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious...
CVE-2024-45496CRITICAL9.9A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Pla...
CVE-2024-44202MEDIUM5.3An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadO...
CVE-2024-44198MEDIUM5.5An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS ...
CVE-2024-44191MEDIUM5.5This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, i...
CVE-2024-44190MEDIUM5.5A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7...
CVE-2024-44189HIGH7.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. A logic issue existed where a pro...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now