2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7846MEDIUM5.4YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied bloc...
CVE-2024-47227MEDIUM6.1iRedAdmin before 2.6 allows XSS, e.g., via order_name.
CVE-2024-9092MEDIUM6.1A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as proble...
CVE-2024-44048MEDIUM6.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-43996MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit ...
CVE-2024-9089MEDIUM5.4A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue ...
CVE-2024-40703MEDIUM5.5IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Re...
CVE-2024-9084MEDIUM5.4A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u...
CVE-2024-9083MEDIUM4.8A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects ...
CVE-2024-9077MEDIUM5.4A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. A...
CVE-2024-47226MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of t...
CVE-2024-9075MEDIUM5.4A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnera...
CVE-2024-9048MEDIUM6.1A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerab...
CVE-2024-8680MEDIUM5.5The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ...
CVE-2024-6787MEDIUM5.9This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it ...
CVE-2024-6786MEDIUM6.5The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling the...
CVE-2024-46647MEDIUM6.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
CVE-2024-46646MEDIUM6.5eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
CVE-2024-46644MEDIUM6.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
CVE-2024-45793MEDIUM4.8Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The foll...
CVE-2024-46654MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows at...
CVE-2024-45229MEDIUM6.6The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen,...
CVE-2024-42346MEDIUM5.4Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, ...
CVE-2024-42697MEDIUM6.1Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to...
CVE-2024-9040MEDIUM5.5A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now