2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39668MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppar...
CVE-2024-39667MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes El...
CVE-2024-39665MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YMC Filter ...
CVE-2024-39662MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb ...
CVE-2024-39661MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendTheme...
CVE-2024-39660MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow ...
CVE-2024-39659MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaM...
CVE-2024-39655MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll ...
CVE-2024-39652MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite...
CVE-2024-39649MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essent...
CVE-2024-39648MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter...
CVE-2024-39637MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through...
CVE-2024-32931MEDIUM5.7Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
CVE-2024-39630MEDIUM5.5Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This i...
CVE-2024-38772MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets fo...
CVE-2024-4353MEDIUM4.8Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board ins...
CVE-2024-7359MEDIUM6.1A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic....
CVE-2024-7211MEDIUM6.1The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulner...
CVE-2024-41962MEDIUM6.3Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authori...
CVE-2024-41926MEDIUM4.3Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the co...
CVE-2024-41162MEDIUM4.3Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification ...
CVE-2024-39839MEDIUM4.3Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their o...
CVE-2024-39837MEDIUM5.4Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious r...
CVE-2024-39274MEDIUM6.5Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the...
CVE-2024-36492MEDIUM6.4Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now