2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5647MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups li...
CVE-2024-9017MEDIUM6.4The PeepSo Core: Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Group Description fiel...
CVE-2024-11405MEDIUM6.1The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email a...
CVE-2024-46993MEDIUM4.4Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In ...
CVE-2024-12915MEDIUM4.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Sof...
CVE-2024-52900MEDIUM5.4IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scrip...
CVE-2024-39730MEDIUM5.4IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim....
CVE-2024-36347MEDIUM6.4Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri...
CVE-2024-56915MEDIUM6.5Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.
CVE-2024-11584MEDIUM5.3cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grant...
CVE-2024-57708MEDIUM5.7An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __...
CVE-2024-51984MEDIUM6.8An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled ...
CVE-2024-51981MEDIUM5.3An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c...
CVE-2024-51980MEDIUM5.3An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open ...
CVE-2024-51977MEDIUM5.3An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t...
CVE-2024-56916MEDIUM6.1In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) d...
CVE-2024-56918MEDIUM6.1In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authen...
CVE-2024-3511MEDIUM4.3An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned f...
CVE-2024-54172MEDIUM4.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera...
CVE-2024-54183MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera...
CVE-2024-40570MEDIUM6.5SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_data...
CVE-2024-25573MEDIUM6.9Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScrip...
CVE-2024-38825MEDIUM6.4The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate whic...
CVE-2024-55567MEDIUM6.7Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55....
CVE-2024-44906MEDIUM6.5uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now