2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12237MEDIUM4.3The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in...
CVE-2024-56332MEDIUM5.3Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions ...
CVE-2024-56412MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56411MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56410MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-36613MEDIUM6.2FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potent...
CVE-2024-56514MEDIUM5.3Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes ...
CVE-2024-56409MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56366MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56365MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56408MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-5591MEDIUM4.3IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detaile...
CVE-2024-41780MEDIUM4.6IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to n...
CVE-2024-12132MEDIUM4.3The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-53839MEDIUM5.5In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. Th...
CVE-2024-53836MEDIUM6.7In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buffer overflow. This c...
CVE-2024-8447MEDIUM5.9A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution...
CVE-2024-48197MEDIUM4.7Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the...
CVE-2024-11717MEDIUM6.3Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When...
CVE-2024-11716MEDIUM5.3While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in log...
CVE-2024-56414MEDIUM5.5Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (W...
CVE-2024-56413MEDIUM6.1Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows...
CVE-2024-55542MEDIUM4.4Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are aff...
CVE-2024-55541MEDIUM6.1Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ...
CVE-2024-12907MEDIUM5.3Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parame...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now