2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5410MEDIUM5.4Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects ...
CVE-2024-28880MEDIUM6.5Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the prod...
CVE-2024-34923MEDIUM6.1In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before...
CVE-2024-36105MEDIUM5.3dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to ...
CVE-2024-36037MEDIUM5.5Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session...
CVE-2024-36036MEDIUM4.2Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive...
CVE-2024-35238MEDIUM5.3Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerab...
CVE-2024-27310MEDIUM6.5Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP inpu...
CVE-2024-35236MEDIUM4.8Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious s...
CVE-2024-35229MEDIUM5.3ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a ve...
CVE-2024-32978MEDIUM6.6Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecu...
CVE-2024-5409MEDIUM6.1RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker coul...
CVE-2024-5408MEDIUM6.1Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnera...
CVE-2024-5406MEDIUM6.3A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text an...
CVE-2024-5405MEDIUM6.3A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via /tools/redis.php page in the k, hash...
CVE-2024-36383MEDIUM5.3An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the st...
CVE-2024-4534MEDIUM6.1The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing saniti...
CVE-2024-4533MEDIUM6.5The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a ...
CVE-2024-4532MEDIUM6.4The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-4530MEDIUM6.3The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-4529MEDIUM5The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-3939MEDIUM5.4The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-35297MEDIUM4.7Cross-site scripting vulnerability exists in WP Booking versions prior to 2.4.5. If this vulnerability is exploited, an ...
CVE-2024-35291MEDIUM6.1Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is e...
CVE-2024-36384MEDIUM6.1Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now