2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-54356MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee...
CVE-2024-54354MEDIUM6.5Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termi...
CVE-2024-37251MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced...
CVE-2024-12092MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE...
CVE-2024-12091MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER...
CVE-2024-12090MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE...
CVE-2024-12089MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER...
CVE-2024-12362MEDIUM5.3A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function ...
CVE-2024-54682MEDIUM4.9Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size fo...
CVE-2024-54083MEDIUM6.5Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the ...
CVE-2024-48872MEDIUM4.8Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrent...
CVE-2024-9679MEDIUM5.3A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previousl...
CVE-2024-9678MEDIUM4.9An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arb...
CVE-2024-12645MEDIUM6.5The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w...
CVE-2024-5333MEDIUM5.3The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticat...
CVE-2024-56112MEDIUM6.1CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.
CVE-2024-56087MEDIUM5.9An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template...
CVE-2024-56085MEDIUM5.9An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template...
CVE-2024-11841MEDIUM5.4The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes be...
CVE-2024-8650MEDIUM5.3An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6...
CVE-2024-8116MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17....
CVE-2024-8798MEDIUM6.5No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client....
CVE-2024-56074MEDIUM5.5gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.
CVE-2024-11720MEDIUM6.1The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms ...
CVE-2024-12628MEDIUM4.4The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' paramete...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now