2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39473MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of...
CVE-2024-39472MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the leg...
CVE-2024-36041HIGH7.8KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ...
CVE-2024-34481MEDIUM6.1drupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page.
CVE-2024-32498MEDIUM6.5An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file...
CVE-2024-39943HIGH8.8rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth...
CVE-2024-39937HIGH7.5supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.
CVE-2024-39936MEDIUM5.9An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x th...
CVE-2024-39935HIGH8.8jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated u...
CVE-2024-6511MEDIUM6.1A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is th...
CVE-2024-39934HIGH7.8Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup ...
CVE-2024-37474MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: f...
CVE-2024-37472MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice ...
CVE-2024-37471MEDIUM6.1Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core:...
CVE-2024-37476MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack ...
CVE-2024-6513Rejected reason: CVE assigned by mistake as a duplicate.
CVE-2024-39933HIGH7.7Gogs through 0.13.0 allows argument injection during the tagging of a new release.
CVE-2024-39932CRITICAL9.9Gogs through 0.13.0 allows argument injection during the previewing of changes.
CVE-2024-39931CRITICAL9.9Gogs through 0.13.0 allows deletion of internal files.
CVE-2024-39930CRITICAL9.9The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code ...
CVE-2024-39929MEDIUM5.4Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filenam...
CVE-2024-22277MEDIUM5.4VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to ...
CVE-2024-6506HIGH8.2Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This ...
CVE-2024-39211MEDIUM5.3Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response ...
CVE-2024-39165CRITICAL9.8QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary cod...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now