2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-52592MEDIUM5.3Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.u...
CVE-2024-52590MEDIUM6.5Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService...
CVE-2024-52579MEDIUM5.4Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check t...
CVE-2024-51470MEDIUM6.5IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE...
CVE-2024-49201MEDIUM4.3Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensit...
CVE-2024-47039MEDIUM5.5In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This...
CVE-2024-55089MEDIUM4.1Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because ...
CVE-2024-55492MEDIUM6.1Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).
CVE-2024-45082MEDIUM5.2IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing...
CVE-2024-41752MEDIUM6.1IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker ...
CVE-2024-25042MEDIUM6.1IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripti...
CVE-2024-52361MEDIUM5.7IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be re...
CVE-2024-56128MEDIUM5.3Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafk...
CVE-2024-50570MEDIUM5A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 th...
CVE-2024-55997MEDIUM6.5Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-locati...
CVE-2024-52485MEDIUM6.5Missing Authorization vulnerability in Yudiz Solutions Ltd. WP Menu Image wp-menu-image allows Exploiting Incorrectly Co...
CVE-2024-11926MEDIUM6.5The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-11291MEDIUM5.3The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2024-47104MEDIUM6.8IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with auth...
CVE-2024-12554MEDIUM5.4The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2024-12454MEDIUM6.1The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2024-12340MEDIUM4.3The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-11295MEDIUM5.3The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-56175MEDIUM6.1In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ...
CVE-2024-56173MEDIUM4.7In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now