2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-40722MEDIUM4.3The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate th...
CVE-2024-38878MEDIUM6.5A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (A...
CVE-2024-4643MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-40719MEDIUM6.5The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is ins...
CVE-2024-27182MEDIUM4.9In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator accou...
CVE-2024-42460MEDIUM5.3In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whet...
CVE-2024-42459MEDIUM5.3In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature leng...
CVE-2024-39396MEDIUM5.5InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could le...
CVE-2024-5595MEDIUM5.4The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before output...
CVE-2024-3827MEDIUM5.4The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, a...
CVE-2024-6567MEDIUM5.3The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001....
CVE-2024-22278MEDIUM4.3Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configur...
CVE-2024-39647MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Messag...
CVE-2024-39646MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 P...
CVE-2024-39644MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb ...
CVE-2024-39643MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Registratio...
CVE-2024-39631MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker /...
CVE-2024-39629MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill ...
CVE-2024-39627MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely Nex...
CVE-2024-39626MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob @ 5 Star Plugi...
CVE-2024-7368MEDIUM5.4A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vul...
CVE-2024-41965MEDIUM4.2Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a bu...
CVE-2024-41957MEDIUM5.3Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a windo...
CVE-2024-41949MEDIUM6.4biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architec...
CVE-2024-41948MEDIUM5biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architec...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now