2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-58095MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before txBeginAnon() call ...
CVE-2024-58094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before truncation in jfs_t...
CVE-2024-58092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Ge...
CVE-2024-10680MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could ...
CVE-2024-13452MEDIUM6.1The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-49200MEDIUM6.4An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential D...
CVE-2024-44843MEDIUM5.9An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbit...
CVE-2024-42200MEDIUM5.4HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validat...
CVE-2024-42189MEDIUM6.5HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an ...
CVE-2024-13177MEDIUM5.2Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the ...
CVE-2024-11084MEDIUM6.3Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whet...
CVE-2024-45712MEDIUM5.4SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be...
CVE-2024-13610MEDIUM4.8The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, ...
CVE-2024-13207MEDIUM4.8The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which ...
CVE-2024-49825MEDIUM4.3IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through ...
CVE-2024-49709MEDIUM4.4Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attack...
CVE-2024-49708MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An ...
CVE-2024-49707MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-49706MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 enco...
CVE-2024-49705MEDIUM6.5Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. A...
CVE-2024-13598MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks....
CVE-2024-13597MEDIUM5.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-10090MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-10089MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An ...
CVE-2024-10088MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now