2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45815MEDIUM6.5Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstag...
CVE-2024-8951MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vu...
CVE-2024-45812MEDIUM6.4Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobb...
CVE-2024-45811MEDIUM4.8Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be retu...
CVE-2024-45606MEDIUM4.3Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rul...
CVE-2024-45605MEDIUM4.3Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user is...
CVE-2024-45604MEDIUM4.3Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the docume...
CVE-2024-8660MEDIUM4.8Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. S...
CVE-2024-45803MEDIUM6.1Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cr...
CVE-2024-45612MEDIUM5.3Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, whic...
CVE-2024-45537MEDIUM6.5Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionali...
CVE-2024-45384MEDIUM5.3Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j ...
CVE-2024-8796MEDIUM5.3Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120...
CVE-2024-38380MEDIUM5.4This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser...
CVE-2024-8939MEDIUM6.2A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vll...
CVE-2024-38860MEDIUM6.1Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious li...
CVE-2024-8897MEDIUM6.1Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a t...
CVE-2024-8761MEDIUM6.1The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. Thi...
CVE-2024-8490MEDIUM6.5The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-8093MEDIUM6.5The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which cou...
CVE-2024-8092MEDIUM5.4The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-8091MEDIUM6.5The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, whi...
CVE-2024-8052MEDIUM6.1The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as ...
CVE-2024-8051MEDIUM5.4The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-8047MEDIUM6.5The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now