2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38002HIGH8.8The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1...
CVE-2024-26273HIGH8.8Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, an...
CVE-2024-26272HIGH8.8Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, an...
CVE-2024-26271HIGH8.8Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, a...
CVE-2024-50312MEDIUM5.3A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allow...
CVE-2024-50311MEDIUM6.5A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batchi...
CVE-2024-10234HIGH7.3A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. Th...
CVE-2024-9050HIGH7.8A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to proper...
CVE-2024-9231MEDIUM6.1The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ...
CVE-2024-10189MEDIUM5.4The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2024-9987HIGH8.8A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv func...
CVE-2024-35308HIGH8.8A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. Thi...
CVE-2024-9591MEDIUM4.8The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_ima...
CVE-2024-9590MEDIUM4.8The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image me...
CVE-2024-9589MEDIUM4.8The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_met...
CVE-2024-9588MEDIUM5.4The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to...
CVE-2024-9541MEDIUM4.3The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to...
CVE-2024-9627HIGH7.3The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing...
CVE-2024-8852MEDIUM5.3The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2024-10003MEDIUM6.3The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing...
CVE-2024-10002HIGH8.8The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. ...
CVE-2024-9677HIGH7.8The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version ...
CVE-2024-8901HIGH7.5The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio...
CVE-2024-10125HIGH7.5The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#vali...
CVE-2024-47224MEDIUM6.5A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.20...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now