2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-51446MEDIUM5.4A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file ...
CVE-2024-55466MEDIUM6.5An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard ...
CVE-2024-4982MEDIUM6.5A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted gi...
CVE-2024-55651MEDIUM5.4i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and...
CVE-2024-12120MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Count...
CVE-2024-58252MEDIUM5.5Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this...
CVE-2024-39442MEDIUM6.2In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure wi...
CVE-2024-42213MEDIUM5.3HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might...
CVE-2024-42212MEDIUM5.4HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request For...
CVE-2024-51991MEDIUM4.9October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authen...
CVE-2024-11615MEDIUM5.3The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1...
CVE-2024-58237MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet poi...
CVE-2024-58100MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: check changes_pkt_data property for extension ...
CVE-2024-58098MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: track changes_pkt_data property for global fun...
CVE-2024-41753MEDIUM6.1IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross...
CVE-2024-58135MEDIUM5.3Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate a...
CVE-2024-55069MEDIUM5.3ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.
CVE-2024-13860MEDIUM5.4The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ param...
CVE-2024-13859MEDIUM5.4The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_...
CVE-2024-13858MEDIUM5.4The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘in...
CVE-2024-13420MEDIUM4.3Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on ...
CVE-2024-13419MEDIUM5.4Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to ...
CVE-2024-12023MEDIUM6.5The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 ...
CVE-2024-55913MEDIUM5.3IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacke...
CVE-2024-55912MEDIUM5.9IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now