2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-37546MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 I...
CVE-2024-37542MEDIUM6.3Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Im...
CVE-2024-37541MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StaxWP Elementor A...
CVE-2024-37539MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Delower WP ...
CVE-2024-37208MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Robert Macchi WP Scraper.This issue affects WP Scraper: from n/a thr...
CVE-2024-5616MEDIUM4.3A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which al...
CVE-2024-39691MEDIUM4.3matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2...
CVE-2024-39021MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApiData_deal.php?...
CVE-2024-39020MEDIUM6.3idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/vpsApiData_deal.php?...
CVE-2024-39019MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?...
CVE-2024-39174MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute ar...
CVE-2024-39178MEDIUM5.4MyPower vc8100 V100R001C00B030 was discovered to contain an arbitrary file read vulnerability via the component /tcpdump...
CVE-2024-39150MEDIUM5.9vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.
CVE-2024-27717MEDIUM6.5Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a rem...
CVE-2024-27716MEDIUM5.4Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary...
CVE-2024-29318MEDIUM5.4Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file wi...
CVE-2024-6526MEDIUM6.1A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073...
CVE-2024-6505MEDIUM6.8A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the ind...
CVE-2024-23588MEDIUM6.5HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible ...
CVE-2024-6523MEDIUM5.4A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown f...
CVE-2024-39485MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Properly re-initialise notifier ...
CVE-2024-39484MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mmc: davinci: Don't strip remove function when driv...
CVE-2024-39483MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: WARN on vNMI + NMI window iff NMIs are ou...
CVE-2024-39482MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bcache: fix variable length array abuse in btree_it...
CVE-2024-39481MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: mc: Fix graph walk in media_pipeline_start ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now