2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7103MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7...
CVE-2024-13958MEDIUM4.8Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue a...
CVE-2024-13954MEDIUM6.5Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration too...
CVE-2024-13953MEDIUM6.9Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue a...
CVE-2024-13950MEDIUM6.9Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator cre...
CVE-2024-13949MEDIUM6.9Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat...
CVE-2024-13930MEDIUM5.9An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if sessio...
CVE-2024-54188MEDIUM5.3Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root a...
CVE-2024-12093MEDIUM6.8An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2024-9544MEDIUM6.4The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,...
CVE-2024-57529MEDIUM6.1Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary c...
CVE-2024-56428MEDIUM5.5The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the C...
CVE-2024-23337MEDIUM6.5jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning va...
CVE-2024-42922MEDIUM6.5AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
CVE-2024-12561MEDIUM6.1The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versi...
CVE-2024-45641MEDIUM6.5IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate val...
CVE-2024-5878MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox Jav...
CVE-2024-33939MEDIUM5.3Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-...
CVE-2024-51106MEDIUM4.6A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation...
CVE-2024-47893MEDIUM6.5Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or w...
CVE-2024-40120MEDIUM6.5seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_sto...
CVE-2024-8201MEDIUM5.4Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hi...
CVE-2024-51475MEDIUM6.1IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject maliciou...
CVE-2024-9882MEDIUM4.8The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does ...
CVE-2024-9879MEDIUM5.4The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a S...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now