2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53278MEDIUM4.8Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin us...
CVE-2024-49353MEDIUM5.9IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to re...
CVE-2024-49351MEDIUM5.5IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.
CVE-2024-11418MEDIUM6.1The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-11342MEDIUM6.1The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-49596MEDIUM6.5Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged ...
CVE-2024-49595MEDIUM4.9Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability...
CVE-2024-11678MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnera...
CVE-2024-11677MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affec...
CVE-2024-11676MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this is...
CVE-2024-11675MEDIUM5.4A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by th...
CVE-2024-11673MEDIUM4.3A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. T...
CVE-2024-53597MEDIUM6.3masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.
CVE-2024-53101MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and ...
CVE-2024-53100MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and d...
CVE-2024-53097MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm: krealloc: Fix MTE false alarm in __do_krealloc ...
CVE-2024-53556MEDIUM6.1An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a ...
CVE-2024-50671MEDIUM4.3Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles...
CVE-2024-53262MEDIUM5.4SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html ...
CVE-2024-53261MEDIUM5.4SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input fro...
CVE-2024-53258MEDIUM5.3Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 o...
CVE-2024-53599MEDIUM5.4A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to exec...
CVE-2024-53255MEDIUM5.4BoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSO...
CVE-2024-52529MEDIUM5.8Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following ...
CVE-2024-51723MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now