2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-54004MEDIUM4.3Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects ...
CVE-2024-51228MEDIUM6.8An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R...
CVE-2024-37816MEDIUM4.2Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.
CVE-2024-21703MEDIUM6.4This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center a...
CVE-2024-11860MEDIUM6.5A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af...
CVE-2024-46055MEDIUM4.8OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.
CVE-2024-11862MEDIUM5.1Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render hal...
CVE-2024-53635MEDIUM4.8A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COV...
CVE-2024-42328MEDIUM5.5When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allo...
CVE-2024-42326MEDIUM4.4There was discovered a use after free bug in browser.c in the es_browser_get_variant function
CVE-2024-11009MEDIUM4.9The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable...
CVE-2024-11025MEDIUM5.4An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administrat...
CVE-2024-10521MEDIUM4.3The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ...
CVE-2024-10895MEDIUM6.4The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-10580MEDIUM5.3The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form su...
CVE-2024-10175MEDIUM6.4The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cro...
CVE-2024-11083MEDIUM5.3The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-11820MEDIUM5.4A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This is...
CVE-2024-53849MEDIUM4.8editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing)....
CVE-2024-43784MEDIUM5.7lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have ...
CVE-2024-11743MEDIUM4.3A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1....
CVE-2024-11742MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management Syst...
CVE-2024-10240MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting...
CVE-2024-53844MEDIUM6.3E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerab...
CVE-2024-53620MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now