2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53672MEDIUM6.3A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run ...
CVE-2024-51773MEDIUM5.4A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe...
CVE-2024-52548MEDIUM6.7An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, an...
CVE-2024-52546MEDIUM5.3An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerabil...
CVE-2024-52545MEDIUM6.5An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability...
CVE-2024-45676MEDIUM4.3IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insuf...
CVE-2024-41776MEDIUM6.5IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an att...
CVE-2024-53867MEDIUM4.3Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0...
CVE-2024-52815MEDIUM5.3Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received ...
CVE-2024-37303MEDIUM5.3Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote part...
CVE-2024-25035MEDIUM5.3IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of...
CVE-2024-53999MEDIUM5.4Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor...
CVE-2024-53257MEDIUM4.9Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vt...
CVE-2024-11200MEDIUM6.1The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter...
CVE-2024-9978MEDIUM5.5in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-12082MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-11326MEDIUM6.1The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-12062MEDIUM4.3The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in...
CVE-2024-11782MEDIUM5.4The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' short...
CVE-2024-11325MEDIUM5.2The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add...
CVE-2024-11866MEDIUM6.4The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map'...
CVE-2024-11844MEDIUM4.3The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-11898MEDIUM5.4The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin...
CVE-2024-11853MEDIUM6.4The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versio...
CVE-2024-11805MEDIUM6.1The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now