2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-41513MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote atta...
CVE-2024-38039MEDIUM5.4There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, auth...
CVE-2024-38038MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 which may allow a remote, unauthenticated...
CVE-2024-38037MEDIUM6.1There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthe...
CVE-2024-38036MEDIUM5.4There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, una...
CVE-2024-25707MEDIUM4.8There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a rem...
CVE-2024-25702MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 11.1 and below ...
CVE-2024-25701MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Experience Builder versions 11...
CVE-2024-25694MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 11.1 and below that m...
CVE-2024-25691MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unaut...
CVE-2024-46409MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts o...
CVE-2024-47765MEDIUM6.1Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential c...
CVE-2024-9410MEDIUM5.3Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping ...
CVE-2024-9484MEDIUM5.5An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on Ma...
CVE-2024-9483MEDIUM5.5A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 2...
CVE-2024-9482MEDIUM5.5An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS ...
CVE-2024-9481MEDIUM5.5An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS ...
CVE-2024-8499MEDIUM6.1The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-47657MEDIUM6.5This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An aut...
CVE-2024-47653MEDIUM6.5This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requ...
CVE-2024-47651MEDIUM6.5This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint...
CVE-2024-9271MEDIUM5.4The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ...
CVE-2024-9071MEDIUM5.4The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-9435MEDIUM6.1The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via U...
CVE-2024-9306MEDIUM4.8The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now