2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-44843MEDIUM5.9An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbit...
CVE-2024-42200MEDIUM5.4HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validat...
CVE-2024-42189MEDIUM6.5HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an ...
CVE-2024-13177MEDIUM5.2Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the ...
CVE-2024-11084MEDIUM6.3Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whet...
CVE-2024-45712MEDIUM5.4SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be...
CVE-2024-13610MEDIUM4.8The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, ...
CVE-2024-13207MEDIUM4.8The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which ...
CVE-2024-49825MEDIUM4.3IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through ...
CVE-2024-49709MEDIUM4.4Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attack...
CVE-2024-49708MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An ...
CVE-2024-49707MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-49706MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 enco...
CVE-2024-49705MEDIUM6.5Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. A...
CVE-2024-13598MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks....
CVE-2024-13597MEDIUM5.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-10090MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-10089MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An ...
CVE-2024-10088MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-10087MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-9230MEDIUM5.9The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set...
CVE-2024-13338MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2024-13337MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2024-11679MEDIUM6.7An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could all...
CVE-2024-52282MEDIUM6.2A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now