2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8729MEDIUM6.1The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add...
CVE-2024-8513MEDIUM5.3The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable...
CVE-2024-7048MEDIUM5.4In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/...
CVE-2024-48942MEDIUM5.9The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to eas...
CVE-2024-48941MEDIUM5.4The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to byp...
CVE-2024-8264MEDIUM5.5Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent...
CVE-2024-48933MEDIUM6.1A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary we...
CVE-2024-7041MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerabili...
CVE-2024-38818MEDIUM6.7VMware NSX contains a local privilege escalation vulnerability.  An authenticated malicious actor may exploit this vuln...
CVE-2024-38817MEDIUM6.7VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may ...
CVE-2024-38815MEDIUM4.3VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL an...
CVE-2024-30118MEDIUM5.7HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in...
CVE-2024-47833MEDIUM6.5Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine lear...
CVE-2024-47828MEDIUM6.5ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to de...
CVE-2024-47816MEDIUM6.4ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the ...
CVE-2024-47815MEDIUM6IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a var...
CVE-2024-47812MEDIUM6ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface st...
CVE-2024-47763MEDIUM5.5Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with st...
CVE-2024-9471MEDIUM4.7A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated ...
CVE-2024-9470MEDIUM5.3A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view th...
CVE-2024-9469MEDIUM5.5A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W...
CVE-2024-9467MEDIUM6.1A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context ...
CVE-2024-9466MEDIUM6.5A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated atta...
CVE-2024-9464MEDIUM6.5An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary...
CVE-2024-42988MEDIUM4.3Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows auth...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now