2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38536HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A ...
CVE-2024-38535HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Su...
CVE-2024-38534HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Cr...
CVE-2024-37151HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. M...
CVE-2024-28872HIGH8.1The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it...
CVE-2024-6035MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerabil...
CVE-2024-6643Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-6407HIGH7.5CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted m...
CVE-2024-6528MEDIUM6.1CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c...
CVE-2024-5681HIGH7.8CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, a...
CVE-2024-5680MEDIUM5.5CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicio...
CVE-2024-5679HIGH7.1CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a...
CVE-2024-2602HIGH7.8CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could r...
CVE-2024-38433MEDIUM6.7Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7...
CVE-2024-6666HIGH8.8The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all version...
CVE-2024-6624CRITICAL9.8The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3...
CVE-2024-6385CRITICAL9.8An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 p...
CVE-2024-6256MEDIUM5.4The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-5470LOW2.7An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to...
CVE-2024-5257LOW2.7An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to...
CVE-2024-2880LOW2.7An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 p...
CVE-2024-6138MEDIUM4.8The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some o...
CVE-2024-6026MEDIUM5.4The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could ...
CVE-2024-6025MEDIUM5.4The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, ...
CVE-2024-5444MEDIUM5.4The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputt...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now