2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-32468MEDIUM5.4Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulnerabilities existed in...
CVE-2024-11672MEDIUM4.3Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on W...
CVE-2024-11671MEDIUM5.4Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on...
CVE-2024-11670MEDIUM5.4Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earli...
CVE-2024-9666MEDIUM4.7A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack ...
CVE-2024-11662MEDIUM6.3A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This iss...
CVE-2024-10451MEDIUM5.9A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured dur...
CVE-2024-10270MEDIUM6.5A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, ...
CVE-2024-6538MEDIUM5.3A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies al...
CVE-2024-11660MEDIUM5.4A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown ...
CVE-2024-6393MEDIUM4.8The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Image...
CVE-2024-10709MEDIUM6.8The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before out...
CVE-2024-11483MEDIUM5A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by...
CVE-2024-53930MEDIUM5.4WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a...
CVE-2024-53901MEDIUM5.5The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unsp...
CVE-2024-35160MEDIUM6.5IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7...
CVE-2024-11231MEDIUM6.4The 우커머스 네이버페이 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode...
CVE-2024-11229MEDIUM6.4The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add...
CVE-2024-11228MEDIUM6.4The 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pafw...
CVE-2024-11227MEDIUM6.4The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_...
CVE-2024-11199MEDIUM5.4The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rescue_progress...
CVE-2024-10519MEDIUM6.1The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2024-9635MEDIUM6.1The Checkout with Cash App on WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2024-11446MEDIUM6.1The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter ...
CVE-2024-11330MEDIUM6.1The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now