2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-52345MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RobertoAlicata ra_...
CVE-2024-52344MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeies Pvt Ltd Pr...
CVE-2024-52343MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio...
CVE-2024-52342MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio...
CVE-2024-52341MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio...
CVE-2024-10486MEDIUM5.3The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and inclu...
CVE-2024-52585MEDIUM5.4Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vuln...
CVE-2024-52584MEDIUM5.4Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in ver...
CVE-2024-52506MEDIUM6.5Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and sched...
CVE-2024-50849MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote au...
CVE-2024-50848MEDIUM6.5An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldSe...
CVE-2024-48294MEDIUM5.5A NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cau...
CVE-2024-48293MEDIUM6.5Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level...
CVE-2024-43416MEDIUM5.3GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unaut...
CVE-2024-10390MEDIUM6.4The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capab...
CVE-2024-52426MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linear Oy Linear l...
CVE-2024-52425MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladislav Urchenko...
CVE-2024-52424MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in sureshdsk wp-login customizer wp-login-customizer allows Stored XSS.T...
CVE-2024-52423MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify ...
CVE-2024-52422MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. WP Github...
CVE-2024-52419MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clipboard Agency C...
CVE-2024-11304MEDIUM5.1Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertec...
CVE-2024-9526MEDIUM5.4There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipel...
CVE-2024-52318MEDIUM6.1Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31,...
CVE-2024-52317MEDIUM6.5Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response u...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now