2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6813HIGH8.8NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerab...
CVE-2024-6812HIGH7.8IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote att...
CVE-2024-6811HIGH7.8IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote att...
CVE-2024-43411LOW3.1CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in...
CVE-2024-43410HIGH7.5Russh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to...
CVE-2024-43027HIGH8DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_...
CVE-2024-41937MEDIUM6.1Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execut...
CVE-2024-39344HIGH8.1An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication_...
CVE-2024-21690HIGH8.2This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, ...
CVE-2024-43407MEDIUM6.1CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in C...
CVE-2024-43371MEDIUM6.5CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugin...
CVE-2024-41675MEDIUM6.1CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did no...
CVE-2024-41674MEDIUM5.3CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues w...
CVE-2024-8007HIGH8.1A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vuln...
CVE-2024-7885HIGH7.5A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across ...
CVE-2024-28000CRITICAL9.8Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affect...
CVE-2024-37008HIGH7.8A maliciously crafted DWG file, when parsed in Revit, can force a stack-based buffer overflow. A malicious actor can lev...
CVE-2024-7757Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5335CRITICAL9.8The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc...
CVE-2024-6339MEDIUM6.1The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions ...
CVE-2024-7998LOW2.6In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them usin...
CVE-2024-7854CRITICAL9.8The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to ins...
CVE-2024-7651HIGH7.5The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injec...
CVE-2024-7647MEDIUM6.1The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2024-7629MEDIUM5.4The Responsive video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's video settings f...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now