2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-56366MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56365MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56408MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-5591MEDIUM4.3IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detaile...
CVE-2024-41780MEDIUM4.6IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to n...
CVE-2024-12132MEDIUM4.3The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-53839MEDIUM5.5In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. Th...
CVE-2024-53836MEDIUM6.7In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buffer overflow. This c...
CVE-2024-8447MEDIUM5.9A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution...
CVE-2024-48197MEDIUM4.7Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the...
CVE-2024-11717MEDIUM6.3Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When...
CVE-2024-11716MEDIUM5.3While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in log...
CVE-2024-56414MEDIUM5.5Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (W...
CVE-2024-56413MEDIUM6.1Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows...
CVE-2024-55542MEDIUM4.4Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are aff...
CVE-2024-55541MEDIUM6.1Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ...
CVE-2024-12907MEDIUM5.3Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parame...
CVE-2024-55538MEDIUM4Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image ...
CVE-2024-49385MEDIUM5.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True I...
CVE-2024-38732MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue ...
CVE-2024-38731MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Marsian i-amaze allows Cross Site Request Forgery.This issue affects ...
CVE-2024-37931MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Creativthemes Point allows Cross Site Request Forgery.This issue affe...
CVE-2024-37925MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This ...
CVE-2024-37452MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite allows Cross Site Request Forgery.This issue ...
CVE-2024-37438MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Reque...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now