2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12061MEDIUM4.3The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc...
CVE-2024-11254MEDIUM6.1The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the d...
CVE-2024-12513MEDIUM6.4The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONT...
CVE-2024-12500MEDIUM6.4The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-11881MEDIUM6.4The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywavefor...
CVE-2024-11748MEDIUM6.4The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' short...
CVE-2024-11439MEDIUM6.4The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode...
CVE-2024-10973MEDIUM5.7A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGr...
CVE-2024-56142MEDIUM6.5pghoard is a PostgreSQL backup daemon and restore tooling that stores backup data in cloud object stores. A vulnerabilit...
CVE-2024-52792MEDIUM6.5LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LD...
CVE-2024-55059MEDIUM6.1A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certifi...
CVE-2024-55058MEDIUM4.3An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1...
CVE-2024-55057MEDIUM5.4Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unautho...
CVE-2024-55056MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /u...
CVE-2024-12539MEDIUM6.5An issue was discovered where improper authorization controls affected certain queries that could allow a malicious acto...
CVE-2024-11993MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA thro...
CVE-2024-55514MEDIUM6.3A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue...
CVE-2024-56139MEDIUM6.9pdftools is a high level tools to convert PDF files to ePUB formats. In versions up to and including 0.5.0 maliciously c...
CVE-2024-49818MEDIUM4.3IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensi...
CVE-2024-49817MEDIUM4.4IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files ...
CVE-2024-49816MEDIUM4.4IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log...
CVE-2024-53144MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS parin...
CVE-2024-37607MEDIUM6.5A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Servi...
CVE-2024-37606MEDIUM6.5A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (D...
CVE-2024-37605MEDIUM6.5A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now