2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39579MEDIUM6.7Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local...
CVE-2024-39578MEDIUM6.3Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. ...
CVE-2024-44945HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use ...
CVE-2024-5212MEDIUM6.1The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ paramet...
CVE-2024-3886MEDIUM6.1The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ paramet...
CVE-2024-7435HIGH8.8The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via des...
CVE-2024-39747CRITICAL9.8IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functi...
CVE-2024-8006MEDIUM4.4Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture ...
CVE-2024-45304MEDIUM6.5Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability ...
CVE-2024-6586HIGH7.3Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and s...
CVE-2024-6585MEDIUM5.4Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionali...
CVE-2024-8348CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management Syste...
CVE-2024-8347CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected b...
CVE-2024-8285MEDIUM5.9A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured co...
CVE-2024-44684MEDIUM6.1TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "C...
CVE-2024-44683MEDIUM6.1Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
CVE-2024-44682MEDIUM6.1ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing ...
CVE-2024-8346CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affec...
CVE-2024-42379Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-38868HIGH8.3Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.Thi...
CVE-2024-21658MEDIUM4.3discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topi...
CVE-2024-8345CRITICAL9.8A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. Affected by this issue is...
CVE-2024-8344HIGH8.8A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. Affected by this ...
CVE-2024-8235MEDIUM6.2A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corne...
CVE-2024-6204HIGH8.1Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now