2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39505MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/komeda: check for error-valued pointer komeda_...
CVE-2024-39504MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: validate mandatory meta and p...
CVE-2024-39503HIGH7In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix race between namespace cleanu...
CVE-2024-39502HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ionic: fix use after netif_napi_del() When queues ...
CVE-2024-39501Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-39500MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: sock_map: avoid race between sock_map_close and sk_...
CVE-2024-39499HIGH7.1In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event...
CVE-2024-39498MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/mst: Fix NULL pointer dereference at drm_dp_add...
CVE-2024-39497MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, ...
CVE-2024-39496HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix use-after-free due to race with d...
CVE-2024-39495HIGH7.8In the Linux kernel, the following vulnerability has been resolved: greybus: Fix use-after-free bug in gb_interface_rel...
CVE-2024-39494HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name -...
CVE-2024-39340HIGH8.8The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verificatio...
CVE-2024-36522CRITICAL9.8The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when proc...
CVE-2024-6328CRITICAL9.8The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypa...
CVE-2024-6353MEDIUM6.5The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all ...
CVE-2024-6625MEDIUM5.5The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-6588MEDIUM6.4The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
CVE-2024-6555MEDIUM5.3The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to...
CVE-2024-6024HIGH8.8The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which c...
CVE-2024-6023HIGH8.8The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow a...
CVE-2024-6022HIGH8.8The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could...
CVE-2024-5811MEDIUM5.4The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could ...
CVE-2024-5626MEDIUM6.1The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-4753MEDIUM4.8The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could all...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now