2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25876MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitr...
CVE-2024-25875MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitr...
CVE-2024-25874MEDIUM5.4A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to exec...
CVE-2024-25873MEDIUM5.4Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote m...
CVE-2024-23094HIGH8.8Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_med...
CVE-2024-26287Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-25021HIGH8.4IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execut...
CVE-2024-1104HIGH7.5An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all us...
CVE-2024-0220HIGH8.1B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the...
CVE-2024-26578MEDIUM5.9Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ...
CVE-2024-23349MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This...
CVE-2024-22393CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through...
CVE-2024-26491MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CM...
CVE-2024-26490MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execut...
CVE-2024-26489MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allo...
CVE-2024-1053MEDIUM4.3The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...
CVE-2024-0903MEDIUM6.1The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera...
CVE-2024-27283HIGH7.2A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload po...
CVE-2024-26484MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers...
CVE-2024-26483HIGH8.8An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbit...
CVE-2024-26482HIGH7.1An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes ...
CVE-2024-26481MEDIUM4.7Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.
CVE-2024-25801MEDIUM6.1SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload i...
CVE-2024-23137HIGH7.8A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uni...
CVE-2024-23136HIGH7.8A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now