2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10087MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-9230MEDIUM5.9The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set...
CVE-2024-13338MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2024-13337MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2024-11679MEDIUM6.7An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could all...
CVE-2024-52282MEDIUM6.2A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET ...
CVE-2024-51461MEDIUM6.5IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupt...
CVE-2024-13909MEDIUM4.9The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderb...
CVE-2024-13896MEDIUM6.5The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-...
CVE-2024-10894MEDIUM6.4The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc...
CVE-2024-8243MEDIUM6.3The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and i...
CVE-2024-6860MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix setting...
CVE-2024-6857MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body ...
CVE-2024-52980MEDIUM6.5A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the ...
CVE-2024-52974MEDIUM6.5An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana serve...
CVE-2024-54025MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-52962MEDIUM5.3An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4...
CVE-2024-32122MEDIUM4.4A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7...
CVE-2024-41796MEDIUM6.9A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41795MEDIUM6.9A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-41791MEDIUM6.5A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de...
CVE-2024-47261MEDIUM4.351l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have su...
CVE-2024-13820MEDIUM5.3The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-46494MEDIUM5.4A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-38797MEDIUM4.6EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data po...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now