2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-23772MEDIUM6.6An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability ex...
CVE-2024-22405MEDIUM5.5XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted...
CVE-2024-3072MEDIUM4.3The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-1371MEDIUM6.5The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capabi...
CVE-2024-0216MEDIUM6.4The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in v...
CVE-2024-34047MEDIUM4.3O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler.
CVE-2024-34044MEDIUM5.3The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL.
CVE-2024-34043MEDIUM5.3O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message.
CVE-2024-33522MEDIUM6.7In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Cal...
CVE-2024-33401MEDIUM4.4Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum para...
CVE-2024-28294MEDIUM6.5Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.
CVE-2024-33272MEDIUM6.8SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL ...
CVE-2024-33345MEDIUM6.5D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi,...
CVE-2024-34020MEDIUM6.5A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.
CVE-2024-34011MEDIUM6.8Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec...
CVE-2024-23995MEDIUM6.1Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in t...
CVE-2024-4310MEDIUM5.4Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to se...
CVE-2024-33588MEDIUM5.4Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affe...
CVE-2024-33587MEDIUM5.3Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.T...
CVE-2024-33586MEDIUM5.3Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10W...
CVE-2024-33585MEDIUM4.3Missing Authorization vulnerability in Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce.This iss...
CVE-2024-4304MEDIUM5.4 A Cross-Site Scripting XSS vulnerability has been detected on GT3 Soluciones SWAL. This vulnerability consists in a ref...
CVE-2024-33590MEDIUM5Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.Th...
CVE-2024-33589MEDIUM6.5Missing Authorization vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.6.0.
CVE-2024-33593MEDIUM4.3Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now