2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41172HIGH7.5In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit ...
CVE-2024-39457MEDIUM5.4Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is expl...
CVE-2024-32007HIGH7.5An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an at...
CVE-2024-29736CRITICAL9.1A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attac...
CVE-2024-6903HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Record Management System 1.0. Affect...
CVE-2024-6902HIGH8.8A vulnerability classified as critical was found in SourceCodester Record Management System 1.0. Affected by this vulner...
CVE-2024-6799MEDIUM4.3The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2024-6338HIGH8.8The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ paramete...
CVE-2024-40724HIGH7.8Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary ...
CVE-2024-6901HIGH8.8A vulnerability classified as critical has been found in SourceCodester Record Management System 1.0. Affected is an unk...
CVE-2024-6900HIGH8.8A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as critical. This issue affe...
CVE-2024-6205CRITICAL9.8The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using...
CVE-2024-5604MEDIUM5.9The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-6899CRITICAL9.8A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnera...
CVE-2024-21583MEDIUM4.1Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the ...
CVE-2024-21527HIGH8.2Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com...
CVE-2024-6898CRITICAL9.8A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affec...
CVE-2024-38156MEDIUM6.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-35199HIGH8.2TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions...
CVE-2024-35198CRITICAL9.8TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check ...
CVE-2024-30130HIGH7.5HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an a...
CVE-2024-41111HIGH7.2Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all s...
CVE-2024-40642HIGH8.1The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class...
CVE-2024-5997MEDIUM4.3The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modificat...
CVE-2024-6455MEDIUM5.3The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now