2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11180MEDIUM5.4The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Tim...
CVE-2024-13557MEDIUM6.5The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t...
CVE-2024-51477MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an...
CVE-2024-43186MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored ...
CVE-2024-58130MEDIUM6.1In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization...
CVE-2024-58129MEDIUM4.8In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and t...
CVE-2024-58128MEDIUM4.8In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus a...
CVE-2024-6875MEDIUM6.5A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak ...
CVE-2024-39311MEDIUM5.4Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions...
CVE-2024-12619MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17....
CVE-2024-10307MEDIUM5.5An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17...
CVE-2024-55072MEDIUM5.4A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ...
CVE-2024-58091MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/fbdev-dma: Add shadow buffering for deferred I/...
CVE-2024-58090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched/core: Prevent rescheduling when interrupts ar...
CVE-2024-56469MEDIUM6.3IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 ...
CVE-2024-48944MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a reques...
CVE-2024-45361MEDIUM6.5A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation...
CVE-2024-45355MEDIUM5.5A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida...
CVE-2024-45354MEDIUM4.3A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper inp...
CVE-2024-45353MEDIUM4.3An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is ca...
CVE-2024-55965MEDIUM6.5An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development in...
CVE-2024-55963MEDIUM6.5An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the ...
CVE-2024-41643MEDIUM6.8An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell log...
CVE-2024-13411MEDIUM6.4The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2024-13702MEDIUM5.4The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now