2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39702 | MEDIUM | 5.9 | 0.6% | Jul 23, 2024 | In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allo... |
| CVE-2024-6783 | MEDIUM | 4.8 | 0.5% | Jul 23, 2024 | A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker... |
| CVE-2024-4076 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result... |
| CVE-2024-41655 | HIGH | 7.5 | 0.8% | Jul 23, 2024 | TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4... |
| CVE-2024-41319 | CRITICAL | 9.8 | 5.5% | Jul 23, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter ... |
| CVE-2024-40060 | HIGH | 7.5 | 0.6% | Jul 23, 2024 | go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function. |
| CVE-2024-1975 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from... |
| CVE-2024-1737 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYP... |
| CVE-2024-0760 | HIGH | 7.5 | 4.7% | Jul 23, 2024 | A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the atta... |
| CVE-2024-5602 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitra... |
| CVE-2024-4081 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary ... |
| CVE-2024-4080 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in ar... |
| CVE-2024-4079 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code exec... |
| CVE-2024-41839 | LOW | 3.5 | 0.4% | Jul 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou... |
| CVE-2024-41836 | MEDIUM | 5.5 | 0.2% | Jul 23, 2024 | InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that cou... |
| CVE-2024-34128 | MEDIUM | 5.4 | 0.3% | Jul 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-7014 | HIGH | 8.1 | 1.3% | Jul 23, 2024 | EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting ... |
| CVE-2024-29070 | CRITICAL | 9.1 | 0.8% | Jul 23, 2024 | On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend ser... |
| CVE-2024-41012 | MEDIUM | 6.3 | 0.2% | Jul 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close ra... |
| CVE-2024-6420 | HIGH | 8.6 | 1.8% | Jul 23, 2024 | The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect W... |
| CVE-2024-6231 | MEDIUM | 5.9 | 0.3% | Jul 23, 2024 | The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-4260 | MEDIUM | 6.5 | 0.5% | Jul 23, 2024 | The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts vi... |
| CVE-2024-6885 | HIGH | 8.1 | 1.1% | Jul 23, 2024 | The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file... |
| CVE-2024-6828 | HIGH | 7.2 | 1.0% | Jul 23, 2024 | The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization... |
| CVE-2024-1575 | MEDIUM | 6.5 | 0.3% | Jul 23, 2024 | The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now