2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42266MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: make cow_file_range_inline() honor locked_pa...
CVE-2024-42265MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: protect the fetch of ->fd[fd] in do_dup2() from mis...
CVE-2024-42264HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Prevent out of bounds access in performanc...
CVE-2024-42263MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix potential memory leak in the timestamp...
CVE-2024-42262MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix potential memory leak in the performan...
CVE-2024-42261MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in ...
CVE-2024-42260MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in ...
CVE-2024-6459CRITICAL9.8The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the tem...
CVE-2024-6500CRITICAL10The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion ...
CVE-2024-7886HIGH8.5A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected...
CVE-2024-43395HIGH8.2CraftOS-PC 2 is a rewrite of the desktop port of CraftOS from the popular Minecraft mod ComputerCraft using C++ and a mo...
CVE-2024-43472HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2024-43042CRITICAL9.8Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
CVE-2024-43011MEDIUM4.9An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to i...
CVE-2024-43009MEDIUM4.7A reflected cross-site scripting (XSS) vulnerability exists in user/login.php at line 24 in ZZCMS 2023 and earlier. The ...
CVE-2024-43006MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker c...
CVE-2024-43005MEDIUM4.7A reflected cross-site scripting (XSS) vulnerability in the component dl_liuyan_save.php of ZZCMS v2023 allows attackers...
CVE-2024-42850CRITICAL9.8An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity ...
CVE-2024-42849MEDIUM6.5An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change f...
CVE-2024-7646HIGH8.8A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `netwo...
CVE-2024-42758MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enable...
CVE-2024-42639CRITICAL9.8H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as roo...
CVE-2024-42638CRITICAL9.8H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack...
CVE-2024-42637CRITICAL9.8H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker...
CVE-2024-25837MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to exe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now