2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-40590MEDIUM4.8An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio...
CVE-2024-13772MEDIUM5.9The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass...
CVE-2024-13771MEDIUM5.9The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass...
CVE-2024-26006MEDIUM6.1An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below...
CVE-2024-13407MEDIUM6.5The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via...
CVE-2024-55060MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to exe...
CVE-2024-30143MEDIUM4.3HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing...
CVE-2024-9042MEDIUM5.9This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff...
CVE-2024-57062MEDIUM6.7An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive info...
CVE-2024-55198MEDIUM5.3User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct...
CVE-2024-57348MEDIUM6.1Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary c...
CVE-2024-28803MEDIUM6.1Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote att...
CVE-2024-22880MEDIUM4.7Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary...
CVE-2024-13054MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17...
CVE-2024-13887MEDIUM5.3The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Di...
CVE-2024-13703MEDIUM4.3The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2024-34398MEDIUM4.2An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated...
CVE-2024-27763MEDIUM5.3XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostna...
CVE-2024-52362MEDIUM6.5IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11...
CVE-2024-13870MEDIUM5.7An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows...
CVE-2024-58089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_de...
CVE-2024-58088MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock when freeing cgroup storage The ...
CVE-2024-13430MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure i...
CVE-2024-12589MEDIUM5.4The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Base...
CVE-2024-13498MEDIUM5.3The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Info...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now