2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10883MEDIUM6.1The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th...
CVE-2024-10875MEDIUM6.1The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_...
CVE-2024-10533MEDIUM4.3The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check...
CVE-2024-10262MEDIUM6.3The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
CVE-2024-10147MEDIUM6.4The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versio...
CVE-2024-10017MEDIUM6.4The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-10015MEDIUM6.4The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and '...
CVE-2024-10861MEDIUM5.3The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized ...
CVE-2024-10795MEDIUM4.3The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2...
CVE-2024-10786MEDIUM4.3The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capabil...
CVE-2024-51765MEDIUM5.5A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, ...
CVE-2024-51764MEDIUM5.5A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configura...
CVE-2024-50983MEDIUM5.4FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with adm...
CVE-2024-11261MEDIUM6.1A vulnerability, which was classified as critical, was found in SourceCodester Student Record Management System 1.0. Aff...
CVE-2024-49592MEDIUM6.7Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation ...
CVE-2024-45611MEDIUM5.4GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2024-45610MEDIUM6.1GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2024-11217MEDIUM4.9A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug hig...
CVE-2024-49536MEDIUM5.5Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc...
CVE-2024-45609MEDIUM6.1GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2024-3334MEDIUM4.3A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agen...
CVE-2024-24459MEDIUM5.9An invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 a...
CVE-2024-24458MEDIUM5.9An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Ath...
CVE-2024-24457MEDIUM5.9An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEP...
CVE-2024-24455MEDIUM5.9An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now