2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11973MEDIUM6.1The Quran multilanguage Text & Audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'soura...
CVE-2024-11945MEDIUM6.4The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all vers...
CVE-2024-8256MEDIUM5.9In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1....
CVE-2024-45709MEDIUM5.5SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software b...
CVE-2024-11940MEDIUM6.4The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ ...
CVE-2024-11107MEDIUM6.1The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in...
CVE-2024-10708MEDIUM4.9The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high ...
CVE-2024-11205MEDIUM6.5The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-37144MEDIUM6.7Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8....
CVE-2024-47585MEDIUM4.3SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access level...
CVE-2024-47582MEDIUM5.3Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which lead...
CVE-2024-47581MEDIUM4.3SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated us...
CVE-2024-47580MEDIUM6.8An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment....
CVE-2024-47579MEDIUM6.8An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file...
CVE-2024-32732MEDIUM5.3Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information whi...
CVE-2024-9672MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute special...
CVE-2024-55635MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core...
CVE-2024-12393MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core...
CVE-2024-55601MEDIUM5.3Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markd...
CVE-2024-12369MEDIUM4.2A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc...
CVE-2024-54147MEDIUM6.8Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not valid...
CVE-2024-53847MEDIUM5.1The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS...
CVE-2024-52599MEDIUM5.4Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edi...
CVE-2024-54935MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learn...
CVE-2024-11268MEDIUM5.5A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now