2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45270MEDIUM4.3WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero ...
CVE-2024-45269MEDIUM4.3WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carou...
CVE-2024-8370MEDIUM5.4A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the...
CVE-2024-45509MEDIUM6.5In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in t...
CVE-2024-5053MEDIUM4.3The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner...
CVE-2024-8367MEDIUM5.1A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a...
CVE-2024-8366MEDIUM4.7A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This a...
CVE-2024-44946MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. ...
CVE-2024-8108MEDIUM5.4The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in ...
CVE-2024-0111MEDIUM4.4NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect ...
CVE-2024-8276MEDIUM5.4The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-39579MEDIUM6.7Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local...
CVE-2024-39578MEDIUM6.3Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. ...
CVE-2024-5212MEDIUM6.1The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ paramet...
CVE-2024-3886MEDIUM6.1The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ paramet...
CVE-2024-8006MEDIUM4.4Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture ...
CVE-2024-45304MEDIUM6.5Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability ...
CVE-2024-6585MEDIUM5.4Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionali...
CVE-2024-8285MEDIUM5.9A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured co...
CVE-2024-44684MEDIUM6.1TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "C...
CVE-2024-44683MEDIUM6.1Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
CVE-2024-44682MEDIUM6.1ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing ...
CVE-2024-21658MEDIUM4.3discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topi...
CVE-2024-8235MEDIUM6.2A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corne...
CVE-2024-45047MEDIUM6.1svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now