2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39125MEDIUM5.4Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
CVE-2024-39124MEDIUM5.4In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
CVE-2024-32981MEDIUM5.4Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor ...
CVE-2024-29885MEDIUM4.3silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports ...
CVE-2024-28796MEDIUM5.4IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to...
CVE-2024-40636MEDIUM5.3Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud...
CVE-2024-40633MEDIUM5.3Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/ad...
CVE-2024-38446MEDIUM6.5NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the...
CVE-2024-20416MEDIUM6.5A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated,...
CVE-2024-20400MEDIUM4.7A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote ...
CVE-2024-20396MEDIUM6.5A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain acce...
CVE-2024-6833MEDIUM5.9A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintex...
CVE-2024-29120MEDIUM5.9In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as...
CVE-2024-40617MEDIUM6.5Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated atta...
CVE-2024-31979MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements....
CVE-2024-29737MEDIUM4.7In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not str...
CVE-2024-5703MEDIUM4.3The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-5582MEDIUM5.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-39863MEDIUM5.4Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious li...
CVE-2024-6669MEDIUM4.8The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting...
CVE-2024-6033MEDIUM4.3The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized ...
CVE-2024-5255MEDIUM5.4The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ulti...
CVE-2024-5254MEDIUM5.4The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ulti...
CVE-2024-5253MEDIUM5.4The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_...
CVE-2024-5252MEDIUM5.4The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ulti...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now