2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38156MEDIUM6.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-5997MEDIUM4.3The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modificat...
CVE-2024-6455MEDIUM5.3The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-39090MEDIUM6.1The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forger...
CVE-2024-30126MEDIUM4.7HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malic...
CVE-2024-5321MEDIUM6.1A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read contai...
CVE-2024-5625MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console...
CVE-2024-30125MEDIUM6.2HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the s...
CVE-2024-5620MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Cons...
CVE-2024-40648MEDIUM5.4matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method...
CVE-2024-40647MEDIUM5.3sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variabl...
CVE-2024-40644MEDIUM6.8gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another...
CVE-2024-38302MEDIUM5.7Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (St...
CVE-2024-30473MEDIUM6.5Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privile...
CVE-2024-6504MEDIUM5.3Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with netw...
CVE-2024-40725MEDIUM5.3A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type b...
CVE-2024-5555MEDIUM6.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-5554MEDIUM6.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-6705MEDIUM5.5The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,...
CVE-2024-6599MEDIUM4.3The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capabil...
CVE-2024-6175MEDIUM5.4The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modificati...
CVE-2024-5964MEDIUM6.4The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme...
CVE-2024-39682MEDIUM5.4Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up ...
CVE-2024-40402MEDIUM6.3A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulne...
CVE-2024-39126MEDIUM5.4Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now