2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39702MEDIUM5.9In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allo...
CVE-2024-6783MEDIUM4.8A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker...
CVE-2024-4076HIGH7.5Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result...
CVE-2024-41655HIGH7.5TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4...
CVE-2024-41319CRITICAL9.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter ...
CVE-2024-40060HIGH7.5go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.
CVE-2024-1975HIGH7.5If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from...
CVE-2024-1737HIGH7.5Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYP...
CVE-2024-0760HIGH7.5A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the atta...
CVE-2024-5602HIGH7.8A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitra...
CVE-2024-4081HIGH7.8A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary ...
CVE-2024-4080HIGH7.8A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in ar...
CVE-2024-4079HIGH7.8An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code exec...
CVE-2024-41839LOW3.5Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou...
CVE-2024-41836MEDIUM5.5InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that cou...
CVE-2024-34128MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-7014HIGH8.1EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting ...
CVE-2024-29070CRITICAL9.1On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend ser...
CVE-2024-41012MEDIUM6.3In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close ra...
CVE-2024-6420HIGH8.6The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect W...
CVE-2024-6231MEDIUM5.9The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-4260MEDIUM6.5The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts vi...
CVE-2024-6885HIGH8.1The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file...
CVE-2024-6828HIGH7.2The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization...
CVE-2024-1575MEDIUM6.5The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now