2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39442MEDIUM6.2In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure wi...
CVE-2024-42213MEDIUM5.3HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might...
CVE-2024-42212MEDIUM5.4HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request For...
CVE-2024-51991MEDIUM4.9October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authen...
CVE-2024-11615MEDIUM5.3The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1...
CVE-2024-58237MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet poi...
CVE-2024-58100MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: check changes_pkt_data property for extension ...
CVE-2024-58098MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: track changes_pkt_data property for global fun...
CVE-2024-41753MEDIUM6.1IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross...
CVE-2024-58135MEDIUM5.3Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate a...
CVE-2024-55069MEDIUM5.3ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.
CVE-2024-13860MEDIUM5.4The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ param...
CVE-2024-13859MEDIUM5.4The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_...
CVE-2024-13858MEDIUM5.4The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘in...
CVE-2024-13420MEDIUM4.3Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on ...
CVE-2024-13419MEDIUM5.4Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to ...
CVE-2024-12023MEDIUM6.5The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 ...
CVE-2024-55913MEDIUM5.3IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacke...
CVE-2024-55912MEDIUM5.9IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker...
CVE-2024-55910MEDIUM6.5IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenti...
CVE-2024-55909MEDIUM6.5IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expan...
CVE-2024-48906MEDIUM6.1Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.
CVE-2024-11994MEDIUM5.7APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na...
CVE-2024-11390MEDIUM5.4Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro...
CVE-2024-13381MEDIUM4.8The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now