2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9609MEDIUM6.1The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-...
CVE-2024-10897MEDIUM4.3The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing c...
CVE-2024-52613MEDIUM5.5A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Servic...
CVE-2024-49776MEDIUM6.5A negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) v...
CVE-2024-41217MEDIUM6.5A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service ...
CVE-2024-41206MEDIUM6.5A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disc...
CVE-2024-51679MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue aff...
CVE-2024-51156MEDIUM4.707FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/...
CVE-2024-40579MEDIUM5.4Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to ...
CVE-2024-39707MEDIUM5.3Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by def...
CVE-2024-49025MEDIUM4.3Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-10396MEDIUM6.5An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, pos...
CVE-2024-52524MEDIUM6.9Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discove...
CVE-2024-4311MEDIUM5.4zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password chan...
CVE-2024-48284MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Reg...
CVE-2024-1682MEDIUM4.3An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This ...
CVE-2024-50836MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management Sy...
CVE-2024-52505MEDIUM5.4matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-apps...
CVE-2024-42188MEDIUM4.6HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update dat...
CVE-2024-7124MEDIUM5.3Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'fil...
CVE-2024-50838MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management ...
CVE-2024-50837MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management ...
CVE-2024-11210MEDIUM5.4A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of th...
CVE-2024-50843MEDIUM5.3A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows...
CVE-2024-50842MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now