2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8991MEDIUM5.4The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and o...
CVE-2024-8681MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Medi...
CVE-2024-8965MEDIUM5.4The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom ...
CVE-2024-7011MEDIUM6.5Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, ...
CVE-2024-8974MEDIUM4.3Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 ...
CVE-2024-4099MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to ...
CVE-2024-47176MEDIUM5.3CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality inclu...
CVE-2024-45986MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs wh...
CVE-2024-8118MEDIUM5.1In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to writ...
CVE-2024-47174MEDIUM5.9Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.2...
CVE-2024-47171MEDIUM4.3Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p...
CVE-2024-47170MEDIUM4.3Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p...
CVE-2024-47130MEDIUM6.5The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group me...
CVE-2024-47129MEDIUM4.3The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This ...
CVE-2024-47128MEDIUM4.3The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast m...
CVE-2024-47125MEDIUM5.4The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. ...
CVE-2024-47124MEDIUM6.5The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in calls...
CVE-2024-47122MEDIUM6.5In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows...
CVE-2024-47121MEDIUM5.3The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted e...
CVE-2024-47075MEDIUM6.1LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerabil...
CVE-2024-45989MEDIUM4Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Act...
CVE-2024-45987MEDIUM6.5Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vul...
CVE-2024-45985MEDIUM4.7A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allow...
CVE-2024-45984MEDIUM4.7A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an a...
CVE-2024-45838MEDIUM4.3The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now