2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1687MEDIUM5.4The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized e...
CVE-2024-1686MEDIUM4.3The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing author...
CVE-2024-1323MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type ...
CVE-2024-24099MEDIUM5.4Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.
CVE-2024-25166MEDIUM6.1Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfil...
CVE-2024-24720MEDIUM5.3An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information ...
CVE-2024-22543MEDIUM6.1An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges ...
CVE-2024-24721MEDIUM6.5An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute ...
CVE-2024-26149MEDIUM5.3Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified...
CVE-2024-24564MEDIUM5.3Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, star...
CVE-2024-1899MEDIUM5.3An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of servi...
CVE-2024-25770MEDIUM4.3libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.
CVE-2024-27088MEDIUM5.5es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into ...
CVE-2024-27087MEDIUM5.4Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that ...
CVE-2024-25767MEDIUM6.5nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.
CVE-2024-27350MEDIUM5.9Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug B...
CVE-2024-26606MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)po...
CVE-2024-26605MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last m...
CVE-2024-26604MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "kobject: Remove redundant checks for whethe...
CVE-2024-26603MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Stop relying on userspace for info to faul...
CVE-2024-26602MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on s...
CVE-2024-26601MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed i...
CVE-2024-26600MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: phy: ti: phy-omap-usb2: Fix NULL pointer dereferenc...
CVE-2024-26468MEDIUM6.1A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b6...
CVE-2024-26467MEDIUM6.1A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams befo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now