2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35247MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fpga: region: add owner module and take its refcoun...
CVE-2024-34030MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: PCI: of_property: Return error for int_map allocati...
CVE-2024-33847MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: don't allow unaligned truncation on...
CVE-2024-32936MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: Fix races while restarting...
CVE-2024-3264MEDIUM5.3Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows S...
CVE-2024-37233MEDIUM4.3Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This is...
CVE-2024-36038MEDIUM6.3Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerabi...
CVE-2024-4754MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM...
CVE-2024-27136MEDIUM6.1XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser...
CVE-2024-4900MEDIUM6.1The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contr...
CVE-2024-4899MEDIUM5The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high...
CVE-2024-4499MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax ...
CVE-2024-39337MEDIUM6.5Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.
CVE-2024-39334MEDIUM6.5MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a...
CVE-2024-6273MEDIUM6.1A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by ...
CVE-2024-6267MEDIUM4.8A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b...
CVE-2024-6252MEDIUM6.1A vulnerability has been found in Zorlan SkyCaiji up to 2.8 and classified as problematic. Affected by this vulnerabilit...
CVE-2024-6251MEDIUM6.1A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. Affected is an unknown function of the...
CVE-2024-38379MEDIUM4.8Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these ...
CVE-2024-5596MEDIUM6.3The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2024-4940MEDIUM6.1An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows a...
CVE-2024-3593MEDIUM5.4The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8....
CVE-2024-4874MEDIUM4.3The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc...
CVE-2024-21517MEDIUM6.1This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirec...
CVE-2024-21516MEDIUM4.7This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now