2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45612MEDIUM5.3Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, whic...
CVE-2024-45537MEDIUM6.5Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionali...
CVE-2024-45384MEDIUM5.3Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j ...
CVE-2024-8796MEDIUM5.3Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120...
CVE-2024-38380MEDIUM5.4This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser...
CVE-2024-8939MEDIUM6.2A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vll...
CVE-2024-38860MEDIUM6.1Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious li...
CVE-2024-8897MEDIUM6.1Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a t...
CVE-2024-8761MEDIUM6.1The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. Thi...
CVE-2024-8490MEDIUM6.5The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-8093MEDIUM6.5The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which cou...
CVE-2024-8092MEDIUM5.4The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-8091MEDIUM6.5The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, whi...
CVE-2024-8052MEDIUM6.1The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as ...
CVE-2024-8051MEDIUM5.4The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-8047MEDIUM6.5The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which...
CVE-2024-8044MEDIUM6.5The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which...
CVE-2024-8043MEDIUM5.4The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-5170MEDIUM4.8The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which c...
CVE-2024-44202MEDIUM5.3An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadO...
CVE-2024-44198MEDIUM5.5An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS ...
CVE-2024-44191MEDIUM5.5This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, i...
CVE-2024-44190MEDIUM5.5A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7...
CVE-2024-44188MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be a...
CVE-2024-44187MEDIUM6.5A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now