2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39810MEDIUM4.9Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the Elasti...
CVE-2024-45165MEDIUM5.3An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with e...
CVE-2024-7836MEDIUM4.3The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the dup...
CVE-2024-5583MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-42056MEDIUM6.5Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials f...
CVE-2024-8035MEDIUM4.3Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker ...
CVE-2024-8034MEDIUM4.3Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker...
CVE-2024-8033MEDIUM4.3Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker w...
CVE-2024-7981MEDIUM4.3Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp...
CVE-2024-7978MEDIUM4.3Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who c...
CVE-2024-7976MEDIUM4.3Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp...
CVE-2024-7975MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform...
CVE-2024-20466MEDIUM4.9A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2024-41572MEDIUM6.1Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function tha...
CVE-2024-20488MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2024-42550MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management Sy...
CVE-2024-7722MEDIUM4.3Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attack...
CVE-2024-7602MEDIUM6.5Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remo...
CVE-2024-41937MEDIUM6.1Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execut...
CVE-2024-43407MEDIUM6.1CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in C...
CVE-2024-43371MEDIUM6.5CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugin...
CVE-2024-41675MEDIUM6.1CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did no...
CVE-2024-41674MEDIUM5.3CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues w...
CVE-2024-6339MEDIUM6.1The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions ...
CVE-2024-7647MEDIUM6.1The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now