2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3477MEDIUM4.3The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers...
CVE-2024-3472MEDIUM5.9The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which coul...
CVE-2024-2405MEDIUM4.5The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers ...
CVE-2024-33307MEDIUM5.4SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in...
CVE-2024-25676MEDIUM4.7An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanit...
CVE-2024-33431MEDIUM6.5An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via ...
CVE-2024-33424MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary ...
CVE-2024-33393MEDIUM6.2An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted c...
CVE-2024-33304MEDIUM6.1SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users.
CVE-2024-22830MEDIUM5.3Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control wh...
CVE-2024-33442MEDIUM4.3An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component.
CVE-2024-32213MEDIUM5.3The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, ...
CVE-2024-32211MEDIUM5.5An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive informa...
CVE-2024-32210MEDIUM5.3The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default ...
CVE-2024-30176MEDIUM5.3In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared w...
CVE-2024-33518MEDIUM5.3An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the ...
CVE-2024-33513MEDIUM5.9Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protoco...
CVE-2024-20357MEDIUM5.9A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiat...
CVE-2024-24912MEDIUM6.7A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions ...
CVE-2024-4060MEDIUM6.5Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-4059MEDIUM6.5Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data v...
CVE-2024-31413MEDIUM5.9Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was ins...
CVE-2024-28775MEDIUM5.4IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2024-27391MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: do not realloc workqueue everytime ...
CVE-2024-27390MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: remove one synchronize_net() barrier i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now