2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-56340MEDIUM6.5IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker...
CVE-2024-54173MEDIUM4.7IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read ...
CVE-2024-38290MEDIUM5.3In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.
CVE-2024-58042MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rhashtable: Fix potential deadlock by moving schedu...
CVE-2024-58022MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mailbox: th1520: Fix a NULL vs IS_ERR() bug The de...
CVE-2024-54957MEDIUM6.1Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permi...
CVE-2024-53408MEDIUM5.4AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2024-9285MEDIUM5.3A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue ...
CVE-2024-56812MEDIUM5.5IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-54170MEDIUM5.5IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an ineffi...
CVE-2024-54169MEDIUM6.5IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a s...
CVE-2024-13402MEDIUM5.4The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter ...
CVE-2024-13217MEDIUM4.3The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-13734MEDIUM5.4The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Profi...
CVE-2024-5848MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper input validation. ...
CVE-2024-13907MEDIUM6.5The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Serv...
CVE-2024-0392MEDIUM5.4A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 d...
CVE-2024-6261MEDIUM5.4The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-2321MEDIUM5.6An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed direct...
CVE-2024-13647MEDIUM4.3The School Management System – SakolaWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2024-58021MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: HID: winwing: Add NULL check in winwing_init_led() ...
CVE-2024-58020MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Add NULL check in mt_input_configu...
CVE-2024-58019MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvkm/gsp: correctly advance the read pointer of GSP...
CVE-2024-58018MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvkm: correctly calculate the available space of th...
CVE-2024-58017MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: printk: Fix signed integer overflow when defining L...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now