2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13930MEDIUM5.9An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if sessio...
CVE-2024-54188MEDIUM5.3Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root a...
CVE-2024-12093MEDIUM6.8An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2024-9544MEDIUM6.4The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,...
CVE-2024-57529MEDIUM6.1Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary c...
CVE-2024-56428MEDIUM5.5The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the C...
CVE-2024-23337MEDIUM6.5jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning va...
CVE-2024-42922MEDIUM6.5AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
CVE-2024-12561MEDIUM6.1The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versi...
CVE-2024-45641MEDIUM6.5IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate val...
CVE-2024-5878MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox Jav...
CVE-2024-33939MEDIUM5.3Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-...
CVE-2024-51106MEDIUM4.6A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation...
CVE-2024-47893MEDIUM6.5Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or w...
CVE-2024-40120MEDIUM6.5seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_sto...
CVE-2024-8201MEDIUM5.4Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hi...
CVE-2024-51475MEDIUM6.1IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject maliciou...
CVE-2024-9882MEDIUM4.8The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does ...
CVE-2024-9879MEDIUM5.4The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a S...
CVE-2024-9838MEDIUM5.4The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL...
CVE-2024-9765MEDIUM6.5The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of th...
CVE-2024-9711MEDIUM5.4The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w...
CVE-2024-9709MEDIUM5.4The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w...
CVE-2024-9663MEDIUM5.4The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-9662MEDIUM5.4The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now