2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52888MEDIUM5.4For an authenticated end-user the portal may run a script while attempting to display a directory or some file's propert...
CVE-2024-52887MEDIUM5.4Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing...
CVE-2024-53636CRITICAL9.8An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1....
CVE-2024-13812MEDIUM6.5The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
CVE-2024-13808HIGH8.8The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i...
CVE-2024-30152CRITICAL9.8HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain acce...
CVE-2024-56156CRITICAL9Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypa...
CVE-2024-57375LOW2.4Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c...
CVE-2024-6199HIGH7.7An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS ...
CVE-2024-6198HIGH7.7The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the ...
CVE-2024-11917HIGH8.1The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ...
CVE-2024-30127LOW3.2Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
CVE-2024-30147MEDIUM6.1Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
CVE-2024-30114MEDIUM5.4Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
CVE-2024-30113MEDIUM5.4Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the...
CVE-2024-30148MEDIUM4.1Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's file...
CVE-2024-13307MEDIUM5.3The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of d...
CVE-2024-12244MEDIUM4.3An issue has been discovered in access controls could allow users to view certain restricted project information even wh...
CVE-2024-22351MEDIUM6.3IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user ...
CVE-2024-58251LOW2.5In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI t...
CVE-2024-47829MEDIUM6.5pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shorten...
CVE-2024-10306MEDIUM5.4A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <L...
CVE-2024-53569MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System...
CVE-2024-53568MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4...
CVE-2024-33452HIGH7.7An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling v...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now