2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27181HIGH8.8In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted ac...
CVE-2024-38776HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This i...
CVE-2024-42461CRITICAL9.1In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowe...
CVE-2024-42460MEDIUM5.3In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whet...
CVE-2024-42459MEDIUM5.3In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature leng...
CVE-2024-3238HIGH8.8The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2024-39396MEDIUM5.5InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could le...
CVE-2024-39392HIGH7.8InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c...
CVE-2024-5595MEDIUM5.4The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before output...
CVE-2024-3827MEDIUM5.4The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, a...
CVE-2024-7389HIGH7.5The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2024-42458CRITICAL9.8server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-200...
CVE-2024-38482HIGH7.2CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Clus...
CVE-2024-7378CRITICAL9.8A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this...
CVE-2024-7377CRITICAL9.8A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by...
CVE-2024-7376CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Realtime Quiz System 1.0. Affected...
CVE-2024-6567MEDIUM5.3The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001....
CVE-2024-7375CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Simple Realtime Quiz System 1.0. Thi...
CVE-2024-7374CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Simple Realtime Quiz System 1.0. This vulnerability a...
CVE-2024-22278MEDIUM4.3Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configur...
CVE-2024-7373HIGH8.8A vulnerability classified as critical has been found in SourceCodester Simple Realtime Quiz System 1.0. This affects an...
CVE-2024-7372HIGH8.8A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been rated as critical. Affected by ...
CVE-2024-7371HIGH8.8A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been declared as critical. Affected ...
CVE-2024-7370HIGH8.8A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been classified as critical. Affecte...
CVE-2024-39647MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Messag...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now