2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-2926MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg...
CVE-2024-38471MEDIUM6.8Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS com...
CVE-2024-38344MEDIUM5.4A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is ex...
CVE-2024-6383MEDIUM5.3The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might atte...
CVE-2024-39683MEDIUM6.5ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of ...
CVE-2024-37157MEDIUM5.3Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o...
CVE-2024-36122MEDIUM4.3Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o...
CVE-2024-36113MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on t...
CVE-2024-35234MEDIUM6.1Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o...
CVE-2024-33870MEDIUM6.3An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript documen...
CVE-2024-33869MEDIUM5.3An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a cra...
CVE-2024-29510MEDIUM6.3Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with ...
CVE-2024-29507MEDIUM5.4Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont p...
CVE-2024-5821MEDIUM6.2The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file ...
CVE-2024-31223MEDIUM5.3Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration env...
CVE-2024-3332MEDIUM6.5A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
CVE-2024-39248MEDIUM5.4A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via...
CVE-2024-6052MEDIUM5.4Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scr...
CVE-2024-39220MEDIUM6.5BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, A...
CVE-2024-37726MEDIUM6.8Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to...
CVE-2024-6428MEDIUM6.5Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when cre...
CVE-2024-39830MEDIUM5.9Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled,...
CVE-2024-39807MEDIUM5.3Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an...
CVE-2024-39361MEDIUM5.4Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a Rem...
CVE-2024-36257MEDIUM5.3Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now