2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53275MEDIUM5.3Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, t...
CVE-2024-56364MEDIUM5.4SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, w...
CVE-2024-23945MEDIUM5.9Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authentici...
CVE-2024-11230MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ p...
CVE-2024-12901MEDIUM6.9A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown funct...
CVE-2024-52321MEDIUM5.9Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The produc...
CVE-2024-47864MEDIUM5.3home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug...
CVE-2024-56378MEDIUM4.3libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine functio...
CVE-2024-12897MEDIUM5.3A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has ...
CVE-2024-12896MEDIUM6.9A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and clas...
CVE-2024-56314MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated user...
CVE-2024-56313MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated ...
CVE-2024-56312MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenti...
CVE-2024-12893MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this ...
CVE-2024-12892MEDIUM5.4A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this ...
CVE-2024-11852MEDIUM4.3The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for...
CVE-2024-51464MEDIUM4.3IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially craft...
CVE-2024-51463MEDIUM5.4IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker ...
CVE-2024-12883MEDIUM6.1A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vu...
CVE-2024-12875MEDIUM4.9The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Direct...
CVE-2024-12591MEDIUM6.4The MagicPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wb_share_social shortco...
CVE-2024-12558MEDIUM6.5The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of da...
CVE-2024-12408MEDIUM6.1The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to...
CVE-2024-11722MEDIUM5.9The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all ...
CVE-2024-11688MEDIUM6.1The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ver' or 'date' parameter in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now