2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32939LOW3.7Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, ...
CVE-2024-45169CRITICAL9.8An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper de...
CVE-2024-45168CRITICAL9.1An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without...
CVE-2024-45167CRITICAL9.8An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper de...
CVE-2024-45166CRITICAL9.8An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper de...
CVE-2024-45165MEDIUM5.3An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with e...
CVE-2024-45163CRITICAL9.1The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Una...
CVE-2024-7836MEDIUM4.3The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the dup...
CVE-2024-7384HIGH8.8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2024-5583MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-39576HIGH8.8Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low pri...
CVE-2024-43033HIGH8.8JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via...
CVE-2024-42056MEDIUM6.5Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials f...
CVE-2024-28987CRITICAL9.1The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthe...
CVE-2024-8035MEDIUM4.3Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker ...
CVE-2024-8034MEDIUM4.3Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker...
CVE-2024-8033MEDIUM4.3Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker w...
CVE-2024-7981MEDIUM4.3Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp...
CVE-2024-7980HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...
CVE-2024-7979HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...
CVE-2024-7978MEDIUM4.3Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who c...
CVE-2024-7977HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...
CVE-2024-7976MEDIUM4.3Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp...
CVE-2024-7975MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform...
CVE-2024-7974HIGH8.8Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now