2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-40673MEDIUM6.5In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Cod...
CVE-2024-8401MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a...
CVE-2024-7881MEDIUM5.1An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged locati...
CVE-2024-6351MEDIUM4.3A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert
CVE-2024-11954MEDIUM4.8A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func...
CVE-2024-23953MEDIUM6.5Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid s...
CVE-2024-13527MEDIUM5.4The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-13521MEDIUM5.4The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2024-13509MEDIUM6.1The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in al...
CVE-2024-12807MEDIUM4.8The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could...
CVE-2024-12723MEDIUM6.1The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-53881MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm...
CVE-2024-53869MEDIUM5.5NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A suc...
CVE-2024-0147MEDIUM5.5NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been free...
CVE-2024-0140MEDIUM6.8NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data is...
CVE-2024-0137MEDIUM6.5NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le...
CVE-2024-45341MEDIUM6.1A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that appl...
CVE-2024-45336MEDIUM6.1The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ contai...
CVE-2024-22315MEDIUM6.5IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker w...
CVE-2024-27263MEDIUM5.3IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obt...
CVE-2024-28786MEDIUM6.5IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be ...
CVE-2024-56178MEDIUM6.5An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a ...
CVE-2024-54728MEDIUM6.5Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access sys...
CVE-2024-48662MEDIUM6.1Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbit...
CVE-2024-54550MEDIUM4This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now