2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-54179MEDIUM5.4IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier ...
CVE-2024-53025MEDIUM5.5Transient DOS can occur while processing UCI command.
CVE-2024-43056MEDIUM6.5Transient DOS during hypervisor virtual I/O operation in a virtual machine.
CVE-2024-43051MEDIUM5.5Information disclosure while deriving keys for a session for any Widevine use case.
CVE-2024-38426MEDIUM5.3While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-24778MEDIUM6.5Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resou...
CVE-2024-10925MEDIUM5.3A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 1...
CVE-2024-8186MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17....
CVE-2024-53386MEDIUM6.1Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not di...
CVE-2024-53382MEDIUM5.4Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but ...
CVE-2024-36353MEDIUM6.5Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem...
CVE-2024-55907MEDIUM5.3IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno...
CVE-2024-41778MEDIUM6.5IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, whi...
CVE-2024-13546MEDIUM4.3The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...
CVE-2024-13697MEDIUM6.5The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2024-13806MEDIUM6.5The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl...
CVE-2024-13901MEDIUM4.8The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to...
CVE-2024-9217MEDIUM6.1The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us...
CVE-2024-9212MEDIUM6.1The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
CVE-2024-13750MEDIUM6.5The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or...
CVE-2024-13746MEDIUM6.5The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss ...
CVE-2024-13559MEDIUM6.4The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wis...
CVE-2024-13518MEDIUM4.3The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-13358MEDIUM4.3The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to...
CVE-2024-54175MEDIUM5.5IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now