2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38657MEDIUM4.9External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version...
CVE-2024-7141MEDIUM5.9Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.
CVE-2024-55457MEDIUM6.5MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit th...
CVE-2024-54961MEDIUM6.5Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple ...
CVE-2024-54960MEDIUM6.5A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted pa...
CVE-2024-54959MEDIUM6.1Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabli...
CVE-2024-54958MEDIUM6.1Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw al...
CVE-2024-49344MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application estab...
CVE-2024-49337MEDIUM5.4IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation...
CVE-2024-6432MEDIUM5.4The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘conte...
CVE-2024-13855MEDIUM4.3The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2024-13849MEDIUM4.8The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2024-13802MEDIUM5.4The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_e...
CVE-2024-13748MEDIUM4.8The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title paramet...
CVE-2024-13520MEDIUM5.3The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-13888MEDIUM6.1The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This i...
CVE-2024-13155MEDIUM5.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-13445MEDIUM5.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-49780MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system....
CVE-2024-49355MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enab...
CVE-2024-43196MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0  application could allow an authenticated user to manipulate data in the Question...
CVE-2024-6697MEDIUM6.5The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functional...
CVE-2024-6696MEDIUM4.9The product implements access controls via a policy or other feature with the intention to disable or restrict accesses ...
CVE-2024-37363MEDIUM6.5The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (C...
CVE-2024-37362MEDIUM6.3The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauth...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now