2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-50313MEDIUM6.9A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mech...
CVE-2024-47808MEDIUM6.5A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database...
CVE-2024-46894MEDIUM5.4A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p...
CVE-2024-46889MEDIUM6.9A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-...
CVE-2024-36140MEDIUM5.4A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab...
CVE-2024-10323MEDIUM5.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File upl...
CVE-2024-10179MEDIUM6.4The Slickstream: Engagement and Conversions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-9836MEDIUM5.9The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before o...
CVE-2024-9835MEDIUM4.8The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputtin...
CVE-2024-9357MEDIUM6.1The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in al...
CVE-2024-29075MEDIUM4.6Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerab...
CVE-2024-10790MEDIUM5.4The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl...
CVE-2024-11102MEDIUM4.8A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been rated as problematic. Affected b...
CVE-2024-10695MEDIUM4.3The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.1...
CVE-2024-10685MEDIUM6.1The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-10538MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label pa...
CVE-2024-49395MEDIUM5.3In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field b...
CVE-2024-49394MEDIUM5.3In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacke...
CVE-2024-8882MEDIUM4.5A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and ea...
CVE-2024-8881MEDIUM6.8A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version ...
CVE-2024-49393MEDIUM6.5In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker tha...
CVE-2024-11097MEDIUM5.5A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. Thi...
CVE-2024-47593MEDIUM4.3SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the serv...
CVE-2024-47592MEDIUM5.3SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the...
CVE-2024-47588MEDIUM4.7In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors,...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now