2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7390MEDIUM5.3The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2024-7134HIGH7.2The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2024-7090MEDIUM6.1The LH Add Media From Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘lh_add_media_fro...
CVE-2024-7032MEDIUM6.5The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capab...
CVE-2024-7030MEDIUM4.3The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-7013HIGH7.8Stack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execut...
CVE-2024-6883MEDIUM4.3The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthoriz...
CVE-2024-6767MEDIUM5.5The WordSurvey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sounding_title’ parameter in a...
CVE-2024-6568MEDIUM5.3The Flamix: Bitrix24 and Contact Form 7 integrations plugin for WordPress is vulnerable to Full Path Disclosure in all v...
CVE-2024-6508HIGH8An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit gr...
CVE-2024-5880MEDIUM4.3The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-42939MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execu...
CVE-2024-38305HIGH7.3Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the install...
CVE-2024-43882HIGH7In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid...
CVE-2024-43881HIGH7.1In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: change DMA direction while mapping re...
CVE-2024-43880MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_erp: Fix object nesting warning...
CVE-2024-43879MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: handle 2x996 RU allocation in cfg80...
CVE-2024-43878HIGH7.1In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix input error path memory access When ther...
CVE-2024-43877HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In ...
CVE-2024-43876MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI: rcar: Demote WARN() to dev_warn_ratelimited() ...
CVE-2024-43875MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Clean up error handling in vpci_scan...
CVE-2024-43874MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix null pointer dereference in __sev...
CVE-2024-43873HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow The...
CVE-2024-43872MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup under heavy CEQE load CE...
CVE-2024-43871MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: devres: Fix memory leakage caused by driver API dev...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now