2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10045MEDIUM4.3The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-9583MEDIUM5.4The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauth...
CVE-2024-9829MEDIUM6.5The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks...
CVE-2024-31880MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2024-48656MEDIUM4.8Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker...
CVE-2024-48652MEDIUM4.8Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the cont...
CVE-2024-48644MEDIUM5.3Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_230...
CVE-2024-48415MEDIUM5itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastna...
CVE-2024-45526MEDIUM5.3An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send r...
CVE-2024-46903MEDIUM6.5A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose...
CVE-2024-45335MEDIUM5.5Trend Micro Antivirus One, version 3.10.4 and below contains a vulnerability that could allow an attacker to use a speci...
CVE-2024-10183MEDIUM5.2A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges t...
CVE-2024-49211MEDIUM6.1Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.0...
CVE-2024-49210MEDIUM6.1Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A r...
CVE-2024-49209MEDIUM4.3Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to suppo...
CVE-2024-48708MEDIUM5.4Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action ...
CVE-2024-48707MEDIUM5.4Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit wi...
CVE-2024-48706MEDIUM5.4Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform wi...
CVE-2024-46538MEDIUM4.8A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-49373MEDIUM4.3No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an a...
CVE-2024-48929MEDIUM4.2Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and ver...
CVE-2024-48927MEDIUM4.6Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13....
CVE-2024-48925MEDIUM6.5Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version...
CVE-2024-46240MEDIUM4.8Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/co...
CVE-2024-8980MEDIUM6.1The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA throug...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now