2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53281MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functi...
CVE-2024-53280MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center pol...
CVE-2024-53279MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station funct...
CVE-2024-55582MEDIUM5.7Oxide before 6 has unencrypted Control Plane datastores.
CVE-2024-55578MEDIUM4.3Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log f...
CVE-2024-55566MEDIUM6.6ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded...
CVE-2024-55565MEDIUM4.3nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
CVE-2024-55563MEDIUM5.3Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024...
CVE-2024-12348MEDIUM6.1A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is ...
CVE-2024-12347MEDIUM6.9A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This ...
CVE-2024-12346MEDIUM5.3A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unk...
CVE-2024-47107MEDIUM5.4IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed...
CVE-2024-41762MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2024-37071MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user...
CVE-2024-11464MEDIUM6.1The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in ...
CVE-2024-11457MEDIUM6.1The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-11380MEDIUM6.4The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortco...
CVE-2024-12253MEDIUM5.4The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthoriz...
CVE-2024-12128MEDIUM6.1The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected ...
CVE-2024-11374MEDIUM6.1The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-11367MEDIUM6.1The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...
CVE-2024-11183MEDIUM4.8The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-8679MEDIUM6.8The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2024-7894MEDIUM5.3The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugin's license key due to a missing...
CVE-2024-12257MEDIUM6.1The CardGate Payments for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now