2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6449MEDIUM6.5HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote co...
CVE-2024-7269MEDIUM5.4Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ...
CVE-2024-44943MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm: gup: stop abusing try_grab_folio A kernel warn...
CVE-2024-6312MEDIUM6.5The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including,...
CVE-2024-4554MEDIUM5.4Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. Thi...
CVE-2024-39771MEDIUM6.8QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may a...
CVE-2024-6448MEDIUM5.3The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, an...
CVE-2024-7573MEDIUM5.3The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and incl...
CVE-2024-8216MEDIUM5.4A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management Syste...
CVE-2024-5814MEDIUM5.3A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree...
CVE-2024-5288MEDIUM5.9An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA k...
CVE-2024-45037MEDIUM6.4The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers ...
CVE-2024-1544MEDIUM4.9Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod ...
CVE-2024-8209MEDIUM6.1A vulnerability was found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Aff...
CVE-2024-8208MEDIUM6.1A vulnerability has been found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic...
CVE-2024-43788MEDIUM6.1Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capab...
CVE-2024-8200MEDIUM4.3The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for Wor...
CVE-2024-8199MEDIUM4.3The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for Wor...
CVE-2024-40395MEDIUM6.5An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, inclu...
CVE-2024-7941MEDIUM4.3An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified U...
CVE-2024-8207MEDIUM6.7In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating S...
CVE-2024-7791MEDIUM5.4The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-6789MEDIUM6.5A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 2...
CVE-2024-8046MEDIUM6.4The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-7608MEDIUM5.9An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now