2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-42020MEDIUM5.4A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.
CVE-2024-8558MEDIUM4.3A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerab...
CVE-2024-8555MEDIUM6.1A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic...
CVE-2024-8554MEDIUM5.4A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This is...
CVE-2024-40680MEDIUM5.5IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation cau...
CVE-2024-7620MEDIUM6.6The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2024-7112MEDIUM6.5The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘s...
CVE-2024-6010MEDIUM5.3The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and incl...
CVE-2024-1596MEDIUM6.1The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e...
CVE-2024-8538MEDIUM4.3The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in a...
CVE-2024-6849MEDIUM5.4The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-8521MEDIUM6.1A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index o...
CVE-2024-34155MEDIUM4.3Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stac...
CVE-2024-8394MEDIUM6.5When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a p...
CVE-2024-38640MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability...
CVE-2024-32762MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability cou...
CVE-2024-27126MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability ...
CVE-2024-27125MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could a...
CVE-2024-27122MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability ...
CVE-2024-21906MEDIUM4.7An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-21904MEDIUM6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2024-21903MEDIUM4.7An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-21897MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi...
CVE-2024-25584MEDIUM5.3Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This...
CVE-2024-7622MEDIUM4.3The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing cap...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now