2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57062MEDIUM6.7An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive info...
CVE-2024-55198MEDIUM5.3User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct...
CVE-2024-57348MEDIUM6.1Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary c...
CVE-2024-28803MEDIUM6.1Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote att...
CVE-2024-22880MEDIUM4.7Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary...
CVE-2024-13054MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17...
CVE-2024-13887MEDIUM5.3The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Di...
CVE-2024-13703MEDIUM4.3The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2024-34398MEDIUM4.2An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated...
CVE-2024-27763MEDIUM5.3XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostna...
CVE-2024-52362MEDIUM6.5IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11...
CVE-2024-13870MEDIUM5.7An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows...
CVE-2024-58089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_de...
CVE-2024-58088MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock when freeing cgroup storage The ...
CVE-2024-13430MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure i...
CVE-2024-12589MEDIUM5.4The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Base...
CVE-2024-13498MEDIUM5.3The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Info...
CVE-2024-56338MEDIUM4.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-...
CVE-2024-51322MEDIUM5.4Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote C...
CVE-2024-51320MEDIUM5.4Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote C...
CVE-2024-46663MEDIUM6.7A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 a...
CVE-2024-33501MEDIUM6.7Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Forti...
CVE-2024-32123MEDIUM6.7Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMan...
CVE-2024-52285MEDIUM6.9A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-...
CVE-2024-58102MEDIUM6.5An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consum...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now