2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35119MEDIUM5.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2024-28798MEDIUM6.1IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2024-5062MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability ...
CVE-2024-28795MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2024-6415MEDIUM5.1A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is a...
CVE-2024-6414MEDIUM6.9A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown fun...
CVE-2024-5819MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Store...
CVE-2024-6363MEDIUM5.4The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortco...
CVE-2024-5790MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute...
CVE-2024-5666MEDIUM5.4The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter w...
CVE-2024-5942MEDIUM5.4The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an...
CVE-2024-5889MEDIUM6.1The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2024-5192MEDIUM5.4The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps ...
CVE-2024-6405MEDIUM5.4The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-39828MEDIUM6.1R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to ...
CVE-2024-38533MEDIUM6.5ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access...
CVE-2024-38518MEDIUM4.6BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a...
CVE-2024-29040MEDIUM4.3This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Q...
CVE-2024-35156MEDIUM6.5IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error ...
CVE-2024-25053MEDIUM5.9IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certif...
CVE-2024-25041MEDIUM5.4IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cro...
CVE-2024-25031MEDIUM6.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allo...
CVE-2024-35155MEDIUM6.5IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a de...
CVE-2024-38522MEDIUM6.3Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy ap...
CVE-2024-38521MEDIUM6.1Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now