2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-2159MEDIUM4.7The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes ...
CVE-2024-0905MEDIUM6.3The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it b...
CVE-2024-32404MEDIUM6Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execut...
CVE-2024-33670MEDIUM4.3Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a u...
CVE-2024-33669MEDIUM6.8An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned whil...
CVE-2024-33667MEDIUM6.5An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack b...
CVE-2024-33665MEDIUM6.1angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor ...
CVE-2024-33664MEDIUM5.3python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a cra...
CVE-2024-33663MEDIUM6.5python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-...
CVE-2024-3265MEDIUM4.7The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making ...
CVE-2024-31610MEDIUM6.3File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management Syst...
CVE-2024-30939MEDIUM6.8An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attac...
CVE-2024-3623MEDIUM6.5A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in p...
CVE-2024-3508MEDIUM4.3A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endp...
CVE-2024-32649MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s...
CVE-2024-32648MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Prior to version 0.3.0, default functions ...
CVE-2024-32647MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `c...
CVE-2024-32646MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s...
CVE-2024-32645MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect va...
CVE-2024-2905MEDIUM6.2A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds hav...
CVE-2024-32481MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to ver...
CVE-2024-32467MEDIUM6.5MeterSphere is an open source continuous testing platform. Prior to version 2.10.14-lts, members without space permissio...
CVE-2024-31574MEDIUM5Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script
CVE-2024-30890MEDIUM4.7Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categori...
CVE-2024-2467MEDIUM5.9A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plai...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now