2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-26306MEDIUM5.9iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channe...
CVE-2024-25662MEDIUM6.1Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting ...
CVE-2024-24157MEDIUM6.1Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site...
CVE-2024-23236MEDIUM5.5A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to ...
CVE-2024-23229MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5,...
CVE-2024-22910MEDIUM6.1Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code ...
CVE-2024-22344MEDIUM6.1IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code,...
CVE-2024-22064MEDIUM6.5ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set...
CVE-2024-1693MEDIUM4.3The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-1467MEDIUM4.3The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Sid...
CVE-2024-1230MEDIUM4.3The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2....
CVE-2024-1229MEDIUM5.3The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capabil...
CVE-2024-1166MEDIUM6.4The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-0445MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ele...
CVE-2024-0098MEDIUM5.5NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text t...
CVE-2024-33382MEDIUM5.3An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
CVE-2024-25528MEDIUM5.9RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai...
CVE-2024-28971MEDIUM4.9Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log fi...
CVE-2024-24908MEDIUM6.5Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A...
CVE-2024-24788MEDIUM5.9A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.
CVE-2024-24787MEDIUM6.4On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ...
CVE-2024-33612MEDIUM6.8An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impe...
CVE-2024-33604MEDIUM6.1 A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that...
CVE-2024-32761MEDIUM6.5Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running ...
CVE-2024-28889MEDIUM5.9 When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now