2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2231MEDIUM6.5The allows any authenticated user to join a private group due to a missing authorization check on a function
CVE-2024-2040MEDIUM4.3The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make use...
CVE-2024-4543MEDIUM4.3The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-39920MEDIUM4.3The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of...
CVE-2024-32673MEDIUM6.7Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segme...
CVE-2024-4708CRITICAL9.8mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device...
CVE-2024-6453HIGH8.8A vulnerability was found in itsourcecode Farm Management System 1.0. It has been declared as critical. Affected by this...
CVE-2024-24791HIGH7.5The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" hea...
CVE-2024-39326MEDIUM4.4SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectnam...
CVE-2024-39325MEDIUM5.3aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 202...
CVE-2024-39324LOW3.8aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2...
CVE-2024-39322MEDIUM5.5aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 202...
CVE-2024-6452HIGH8.8A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is a...
CVE-2024-39315MEDIUM6.5Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pome...
CVE-2024-38537CRITICAL9.8Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent...
CVE-2024-6382HIGH7.5Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. T...
CVE-2024-6381MEDIUM5.3The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function ...
CVE-2024-6341Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-39894HIGH7.5OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sud...
CVE-2024-39891MEDIUM5.3In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoin...
CVE-2024-39206HIGH7.5An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials ...
CVE-2024-5866MEDIUM4.3Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner...
CVE-2024-5865MEDIUM6.5Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner...
CVE-2024-4467HIGH7.8A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `...
CVE-2024-3826HIGH8.6In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now