2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-55910MEDIUM6.5IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenti...
CVE-2024-55909MEDIUM6.5IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expan...
CVE-2024-48906MEDIUM6.1Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.
CVE-2024-11994MEDIUM5.7APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na...
CVE-2024-11390MEDIUM5.4Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro...
CVE-2024-13381MEDIUM4.8The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could...
CVE-2024-13845MEDIUM5.5The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ...
CVE-2024-30145MEDIUM6.1Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and ...
CVE-2024-30115MEDIUM5.4Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the...
CVE-2024-6029MEDIUM5Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attack...
CVE-2024-9877MEDIUM5.3: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue af...
CVE-2024-58099MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_...
CVE-2024-11922MEDIUM5.4Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an a...
CVE-2024-10635MEDIUM5.3Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthent...
CVE-2024-13688MEDIUM5.3The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protectio...
CVE-2024-52888MEDIUM5.4For an authenticated end-user the portal may run a script while attempting to display a directory or some file's propert...
CVE-2024-52887MEDIUM5.4Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing...
CVE-2024-13812MEDIUM6.5The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
CVE-2024-30147MEDIUM6.1Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
CVE-2024-30114MEDIUM5.4Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
CVE-2024-30113MEDIUM5.4Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the...
CVE-2024-30148MEDIUM4.1Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's file...
CVE-2024-13307MEDIUM5.3The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of d...
CVE-2024-12244MEDIUM4.3An issue has been discovered in access controls could allow users to view certain restricted project information even wh...
CVE-2024-22351MEDIUM6.3IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now