2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39488MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: asm-bug: Add .align 2 to the end of __BUG_EN...
CVE-2024-36453MEDIUM6.1Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions pr...
CVE-2024-36450MEDIUM5.4Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exp...
CVE-2024-6410MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref...
CVE-2024-39330MEDIUM4.3An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.stora...
CVE-2024-39329MEDIUM5.3An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend....
CVE-2024-6550MEDIUM5.3The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up...
CVE-2024-5677MEDIUM4.3The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability...
CVE-2024-4866MEDIUM5.4The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere El...
CVE-2024-25023MEDIUM5.5IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores p...
CVE-2024-22477MEDIUM4.3A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained ...
CVE-2024-22377MEDIUM5.3The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
CVE-2024-39901MEDIUM5.4OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the Op...
CVE-2024-39900MEDIUM5.4OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the...
CVE-2024-38963MEDIUM6.1Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProduct...
CVE-2024-21993MEDIUM6.5SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to di...
CVE-2024-39181MEDIUM6.5Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid pa...
CVE-2024-39072MEDIUM5.5AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calend...
CVE-2024-39031MEDIUM5.4In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, ...
CVE-2024-38959MEDIUM6.1Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attack...
CVE-2024-37865MEDIUM5.9An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive informati...
CVE-2024-34721MEDIUM5.5In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to imprope...
CVE-2024-31314MEDIUM5.5In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could...
CVE-2024-31312MEDIUM5.5In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local ...
CVE-2024-27386MEDIUM6.7A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now