2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4782MEDIUM6.5A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a...
CVE-2024-4781MEDIUM6.5A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a...
CVE-2024-43810MEDIUM5.4In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
CVE-2024-43809MEDIUM6.1In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
CVE-2024-43808MEDIUM5.4In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
CVE-2024-43807MEDIUM5.4In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
CVE-2024-43381MEDIUM5.4reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Store...
CVE-2024-7144MEDIUM5.4The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters...
CVE-2024-42464MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti...
CVE-2024-42463MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti...
CVE-2024-7147MEDIUM6.4The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder p...
CVE-2024-7136MEDIUM6.4The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions u...
CVE-2024-25008MEDIUM6.8Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Valida...
CVE-2024-7501MEDIUM4.2The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2024-7301MEDIUM6.1The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-7422MEDIUM4.3The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-7852MEDIUM5.4A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as problematic. This issue...
CVE-2024-43374MEDIUM4.7The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new fi...
CVE-2024-7844MEDIUM5.4A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affect...
CVE-2024-34742MEDIUM5.5In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to ...
CVE-2024-42488MEDIUM6.8Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and...
CVE-2024-42487MEDIUM4.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1...
CVE-2024-7867MEDIUM6.2In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
CVE-2024-7866MEDIUM5.5In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
CVE-2024-42476MEDIUM6.5In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `st...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now