2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47089MEDIUM6.5This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API ...
CVE-2024-47087MEDIUM6.5This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID ...
CVE-2024-47086MEDIUM6.5This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism ...
CVE-2024-47085MEDIUM6.5This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClic...
CVE-2024-8850MEDIUM6.1The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' ...
CVE-2024-8364MEDIUM5.4The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-pre...
CVE-2024-47059MEDIUM4.3When logging in with the correct username and incorrect weak password, the user receives the notification, that their pa...
CVE-2024-47058MEDIUM4.8With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use...
CVE-2024-47050MEDIUM6.1Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variabl...
CVE-2024-46372MEDIUM6.1DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement manageme...
CVE-2024-43025MEDIUM6.1An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and...
CVE-2024-43024MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to...
CVE-2024-46989MEDIUM5.3spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom...
CVE-2024-46979MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t...
CVE-2024-46978MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible f...
CVE-2024-46959MEDIUM6.5runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows ac...
CVE-2024-46990MEDIUM5Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to loca...
CVE-2024-45813MEDIUM5.3find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route ...
CVE-2024-45298MEDIUM4.3Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the pass...
CVE-2024-6877MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Softwa...
CVE-2024-5959MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Softwa...
CVE-2024-8891MEDIUM5.3An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users a...
CVE-2024-39081MEDIUM4.2An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communicat...
CVE-2024-5682MEDIUM6.9Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library ...
CVE-2024-43188MEDIUM4.9IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthor...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now