2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-33975MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulne...
CVE-2024-7084MEDIUM4.8The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow user...
CVE-2024-7082MEDIUM6.1The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allo...
CVE-2024-6766MEDIUM5.4The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes ...
CVE-2024-6651MEDIUM6.1The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it b...
CVE-2024-6201MEDIUM5.3HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate em...
CVE-2024-6200MEDIUM5.4HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScri...
CVE-2024-5708MEDIUM5.4The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter ...
CVE-2024-39817MEDIUM6.5Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user...
CVE-2024-7008MEDIUM6.1Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
CVE-2024-5963MEDIUM6.7Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue...
CVE-2024-7537MEDIUM5.5oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attacker...
CVE-2024-34343MEDIUM6.1Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo...
CVE-2024-41960MEDIUM4.8mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a Ja...
CVE-2024-41959MEDIUM6.1mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a Ja...
CVE-2024-41820MEDIUM6Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has ...
CVE-2024-41816MEDIUM5.4Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scriptin...
CVE-2024-6361MEDIUM5.4Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all v...
CVE-2024-41381MEDIUM6.1microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\ad...
CVE-2024-41380MEDIUM6.1microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_ta...
CVE-2024-41200MEDIUM5.5A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.
CVE-2024-23357MEDIUM5.5Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
CVE-2024-23350MEDIUM6.5Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integr...
CVE-2024-6710MEDIUM5.4The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a r...
CVE-2024-6498MEDIUM4.8The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its sett...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now