2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12239MEDIUM6.1The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navig...
CVE-2024-10205CRITICAL9.4Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail ...
CVE-2024-11906MEDIUM6.4The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' sho...
CVE-2024-11905MEDIUM6.4The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte...
CVE-2024-11902MEDIUM6.4The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations...
CVE-2024-11900MEDIUM6.4The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-56017HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects...
CVE-2024-55452MEDIUM5.4A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of ...
CVE-2024-55451MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in U...
CVE-2024-55085CRITICAL9.8GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background managem...
CVE-2024-35230MEDIUM5.3GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affe...
CVE-2024-12443MEDIUM6.4The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Sto...
CVE-2024-55554MEDIUM5.4Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet.
CVE-2024-52949HIGH7.5iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th...
CVE-2024-37776MEDIUM4.8A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scri...
CVE-2024-37775HIGH7.5Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh...
CVE-2024-37774HIGH8A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv...
CVE-2024-37773MEDIUM4.8An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject...
CVE-2024-29671CRITICAL9.8Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code vi...
CVE-2024-55557CRITICAL9.8ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti...
CVE-2024-55104HIGH7.2Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin...
CVE-2024-55103HIGH7.2Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile....
CVE-2024-55100MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0...
CVE-2024-55951MEDIUM4.8Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, s...
CVE-2024-55949CRITICAL9.3MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a pr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now