2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-28955MEDIUM5.9Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the ...
CVE-2024-11202MEDIUM6.1Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in v...
CVE-2024-6749MEDIUM6.3Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may exp...
CVE-2024-6476MEDIUM4.2Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user ...
CVE-2024-11002MEDIUM6.3The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh...
CVE-2024-10857MEDIUM6.5The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to...
CVE-2024-10471MEDIUM4.8The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-53278MEDIUM4.8Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin us...
CVE-2024-49353MEDIUM5.9IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to re...
CVE-2024-49351MEDIUM5.5IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.
CVE-2024-11418MEDIUM6.1The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-11342MEDIUM6.1The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-49596MEDIUM6.5Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged ...
CVE-2024-49595MEDIUM4.9Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability...
CVE-2024-11678MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnera...
CVE-2024-11677MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affec...
CVE-2024-11676MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this is...
CVE-2024-11675MEDIUM5.4A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by th...
CVE-2024-11673MEDIUM4.3A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. T...
CVE-2024-53597MEDIUM6.3masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.
CVE-2024-53101MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and ...
CVE-2024-53100MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and d...
CVE-2024-53097MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm: krealloc: Fix MTE false alarm in __do_krealloc ...
CVE-2024-53556MEDIUM6.1An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a ...
CVE-2024-50671MEDIUM4.3Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now