2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47161MEDIUM6.5In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
CVE-2024-45231MEDIUM5.3An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, wh...
CVE-2024-33506MEDIUM4.3An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7...
CVE-2024-8482MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’...
CVE-2024-8431MEDIUM4.3The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data...
CVE-2024-9207MEDIUM6.1The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_...
CVE-2024-8488MEDIUM4.8The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up ...
CVE-2024-8629MEDIUM6.1The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2024-8433MEDIUM6.4The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-47565MEDIUM4.3A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not...
CVE-2024-47563MEDIUM5.3A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not...
CVE-2024-46887MEDIUM6.9The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' e...
CVE-2024-46886MEDIUM5.1The web server of affected devices does not properly validate input that is used for a user redirection. This could allo...
CVE-2024-8964MEDIUM5.4The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG Fi...
CVE-2024-47095MEDIUM5.1Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run...
CVE-2024-34671MEDIUM5.5Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows l...
CVE-2024-34670MEDIUM5.5Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to...
CVE-2024-34663MEDIUM5.5Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory...
CVE-2024-9292MEDIUM6.4The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions...
CVE-2024-9021MEDIUM5.4In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to i...
CVE-2024-8983MEDIUM4.8Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-21533MEDIUM6.5All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specif...
CVE-2024-8925MEDIUM5.3In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data ...
CVE-2024-47594MEDIUM5.4SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip...
CVE-2024-45382MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now