2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10041MEDIUM4.7A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim ...
CVE-2024-10279CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects unknown code o...
CVE-2024-10278CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects an unknown part of the fil...
CVE-2024-10289MEDIUM6.1Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially ...
CVE-2024-10288MEDIUM6.1Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially ...
CVE-2024-10287MEDIUM6.1Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially ...
CVE-2024-10286MEDIUM6.1Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially ...
CVE-2024-10277CRITICAL9.8A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is some unknown functiona...
CVE-2024-8500MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-10276MEDIUM6.1A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability ...
CVE-2024-9530MEDIUM4.3The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2024-43924CRITICAL9.8Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrai...
CVE-2024-10045MEDIUM4.3The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-9947CRITICAL9.8The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4...
CVE-2024-9583MEDIUM5.4The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauth...
CVE-2024-9829MEDIUM6.5The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks...
CVE-2024-50066HIGH7In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix move_normal_pmd/retract_page_tables ...
CVE-2024-9927HIGH7.2The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all vers...
CVE-2024-31880MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2024-7587HIGH7.8Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric ...
CVE-2024-48657HIGH7.2SQL Injection vulnerability in hospital management system in php with source code v.1.0.0 allows a remote attacker to ex...
CVE-2024-48656MEDIUM4.8Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker...
CVE-2024-48652MEDIUM4.8Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the cont...
CVE-2024-48644MEDIUM5.3Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_230...
CVE-2024-48415MEDIUM5itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastna...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now