2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57439MEDIUM4.9An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Ser...
CVE-2024-57438MEDIUM5.4Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves highe...
CVE-2024-57437MEDIUM6.5RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.
CVE-2024-41140MEDIUM6.5Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in th...
CVE-2024-13561MEDIUM6.4The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_ov...
CVE-2024-57514MEDIUM4.8The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi...
CVE-2024-29869MEDIUM5.5Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the fil...
CVE-2024-40674MEDIUM5.3In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a ...
CVE-2024-40673MEDIUM6.5In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Cod...
CVE-2024-8401MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a...
CVE-2024-7881MEDIUM5.1An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged locati...
CVE-2024-6351MEDIUM4.3A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert
CVE-2024-11954MEDIUM4.8A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func...
CVE-2024-23953MEDIUM6.5Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid s...
CVE-2024-13527MEDIUM5.4The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-13521MEDIUM5.4The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2024-13509MEDIUM6.1The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in al...
CVE-2024-12807MEDIUM4.8The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could...
CVE-2024-12723MEDIUM6.1The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-53881MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm...
CVE-2024-53869MEDIUM5.5NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A suc...
CVE-2024-0147MEDIUM5.5NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been free...
CVE-2024-0140MEDIUM6.8NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data is...
CVE-2024-0137MEDIUM6.5NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le...
CVE-2024-45341MEDIUM6.1A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that appl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now