2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-31670MEDIUM6.3rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf f...
CVE-2024-52901MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to impro...
CVE-2024-55633MEDIUM6.5Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access c...
CVE-2024-50584MEDIUM4.4An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_i...
CVE-2024-28145MEDIUM5.9An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malici...
CVE-2024-28144MEDIUM5.5An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaw...
CVE-2024-54122MEDIUM4.7Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may...
CVE-2024-47947MEDIUM4.7Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ...
CVE-2024-36498MEDIUM4.7Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ...
CVE-2024-36494MEDIUM4.7Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ...
CVE-2024-28142MEDIUM4.7Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ...
CVE-2024-12271MEDIUM4.4The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ref’ parameter in a...
CVE-2024-9387MEDIUM6.4An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 bef...
CVE-2024-9367MEDIUM4.3An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and...
CVE-2024-8647MEDIUM5.4An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior t...
CVE-2024-8179MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17....
CVE-2024-54102MEDIUM5.9Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service ...
CVE-2024-54101MEDIUM5.5Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability w...
CVE-2024-54096MEDIUM5.5Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may aff...
CVE-2024-12570MEDIUM6.7An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior ...
CVE-2024-12292MEDIUM4An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 pr...
CVE-2024-12401MEDIUM4.4A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager...
CVE-2024-12333MEDIUM6.5The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8....
CVE-2024-12160MEDIUM6.1The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due ...
CVE-2024-11760MEDIUM6.4The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now