2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10663MEDIUM4.3The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-45206MEDIUM6.5A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests t...
CVE-2024-45204MEDIUM4.3A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak N...
CVE-2024-42457MEDIUM6.5A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by le...
CVE-2024-42451MEDIUM6.5A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th...
CVE-2024-11985MEDIUM4.4An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2...
CVE-2024-11479MEDIUM5.1A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user...
CVE-2024-53672MEDIUM6.3A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run ...
CVE-2024-51773MEDIUM5.4A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe...
CVE-2024-52548MEDIUM6.7An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, an...
CVE-2024-52546MEDIUM5.3An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerabil...
CVE-2024-52545MEDIUM6.5An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability...
CVE-2024-45676MEDIUM4.3IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insuf...
CVE-2024-41776MEDIUM6.5IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an att...
CVE-2024-53867MEDIUM4.3Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0...
CVE-2024-52815MEDIUM5.3Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received ...
CVE-2024-37303MEDIUM5.3Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote part...
CVE-2024-25035MEDIUM5.3IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of...
CVE-2024-53999MEDIUM5.4Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor...
CVE-2024-53257MEDIUM4.9Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vt...
CVE-2024-11200MEDIUM6.1The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter...
CVE-2024-9978MEDIUM5.5in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-12082MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-11326MEDIUM6.1The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-12062MEDIUM4.3The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now