2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-50472MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amil...
CVE-2024-50471MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip ...
CVE-2024-50470MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4W...
CVE-2024-50465MEDIUM6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vin...
CVE-2024-50463MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-phot...
CVE-2024-50307MEDIUM5.5Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If...
CVE-2024-48936MEDIUM5SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit a...
CVE-2024-10435MEDIUM6.3A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown...
CVE-2024-50624MEDIUM5.9ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled m...
CVE-2024-10433MEDIUM6.1A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affecte...
CVE-2024-50615MEDIUM6.5TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp...
CVE-2024-50614MEDIUM6.5TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XM...
CVE-2024-50613MEDIUM6.5libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encod...
CVE-2024-50612MEDIUM5.5libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
CVE-2024-10419MEDIUM6.1A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected ...
CVE-2024-10414MEDIUM4.8A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an...
CVE-2024-10412MEDIUM5.4A vulnerability was found in Poco-z Guns-Medical 1.0. It has been declared as problematic. Affected by this vulnerabilit...
CVE-2024-50602MEDIUM5.9An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_Stop...
CVE-2024-10117MEDIUM5.4The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate short...
CVE-2024-9116MEDIUM6.4The Monkee-Boy Essentials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-10357MEDIUM4.3The Clever Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up ...
CVE-2024-9967MEDIUM5.4The WP show more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_more shortcode ...
CVE-2024-9853MEDIUM6.4The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-9642MEDIUM6.4The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i...
CVE-2024-10092MEDIUM4.3The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now