2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-31859MEDIUM6.3Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which...
CVE-2024-29215MEDIUM4.3Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access contro...
CVE-2024-5365MEDIUM6.5A vulnerability, which was classified as critical, was found in SourceCodester Best House Rental Management System up to...
CVE-2024-5364MEDIUM6.5A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System ...
CVE-2024-5363MEDIUM6.5A vulnerability classified as critical was found in SourceCodester Best House Rental Management System up to 1.0. Affect...
CVE-2024-5354MEDIUM6.5A vulnerability classified as problematic was found in anji-plus AJ-Report up to 1.4.1. This vulnerability affects unkno...
CVE-2024-30056MEDIUM5.4Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-4045MEDIUM5.4The Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation plugin for WordPr...
CVE-2024-5218MEDIUM6.4The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-5229MEDIUM6.4The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Prici...
CVE-2024-4858MEDIUM5.3The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2024-5220MEDIUM5.4The ND Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's upload feature in a...
CVE-2024-36079MEDIUM6.5An issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is cor...
CVE-2024-36049MEDIUM6.5Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list ...
CVE-2024-34995MEDIUM4.3svnWebUI v1.8.3 was discovered to contain an arbitrary file deletion vulnerability via the dirTemps parameter under com....
CVE-2024-33809MEDIUM6.5PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and ...
CVE-2024-33470MEDIUM4.9An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in pla...
CVE-2024-22588MEDIUM6.5Kwik commit 745fd4e2 does not discard unused encryption keys.
CVE-2024-5273MEDIUM4.3Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving rep...
CVE-2024-35595MEDIUM6.1An arbitrary file upload vulnerability in the File Preview function of Xintongda OA v2023.12.30.1 allows attackers to ex...
CVE-2024-35593MEDIUM5.5An arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arb...
CVE-2024-35591MEDIUM5.4An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted...
CVE-2024-5318MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from ...
CVE-2024-5312MEDIUM6.3PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_s...
CVE-2024-4455MEDIUM6.1The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parame...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now