2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3961MEDIUM5.3The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to ...
CVE-2024-5344MEDIUM6.1The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...
CVE-2024-3610MEDIUM5.3The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2024-1955MEDIUM4.3The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2024-1639MEDIUM6.5The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2024-6212MEDIUM6.1A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected...
CVE-2024-38361MEDIUM5.3Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom...
CVE-2024-38359MEDIUM6.5The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability i...
CVE-2024-36071MEDIUM6.3Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files u...
CVE-2024-31586MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerabili...
CVE-2024-30848MEDIUM6.1Cross-site scripting (XSS) vulnerability in SilverSky E-mail service version 5.0.3126 allows remote attackers to inject ...
CVE-2024-6154MEDIUM6.7Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allow...
CVE-2024-38093MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-38082MEDIUM4.7Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-37897MEDIUM5.4SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur...
CVE-2024-37674MEDIUM5.5Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field ...
CVE-2024-37350MEDIUM4.7There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13....
CVE-2024-37346MEDIUM4.9There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13...
CVE-2024-37345MEDIUM5.4There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to ...
CVE-2024-37343MEDIUM5.4There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prio...
CVE-2024-33335MEDIUM6.3SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code...
CVE-2024-28397MEDIUM5.3An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a...
CVE-2024-37222MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Averta Master Slider allows Reflected XSS.This issue affects Master Slider: ...
CVE-2024-6188MEDIUM6.9A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some un...
CVE-2024-5156MEDIUM6.4The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now