2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-29660MEDIUM5.3Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payl...
CVE-2024-25624MEDIUM6.8Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations....
CVE-2024-1726MEDIUM5.3A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoin...
CVE-2024-1102MEDIUM6.5A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as ...
CVE-2024-0874MEDIUM5.3A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented cac...
CVE-2024-33592MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a throu...
CVE-2024-25569MEDIUM6.5An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DIC...
CVE-2024-4172MEDIUM4.3A vulnerability classified as problematic was found in idcCMS 1.35. Affected by this vulnerability is an unknown functio...
CVE-2024-4006MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions start...
CVE-2024-4175MEDIUM5.4Unicode transformation vulnerability in Hyperion affecting version 2.0.15. This vulnerability could allow an attacker to...
CVE-2024-4174MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Hyperion Web Server affecting version 2.0.15. This vulnerability could allow...
CVE-2024-3730MEDIUM5.4The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_su...
CVE-2024-32676MEDIUM5.3Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Imp...
CVE-2024-1347MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 befo...
CVE-2024-4035MEDIUM6.4The Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2024-3994MEDIUM5.4The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-32961MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq B...
CVE-2024-3733MEDIUM5.3The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-3988MEDIUM5.4The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem...
CVE-2024-3929MEDIUM6.4The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for...
CVE-2024-3893MEDIUM4.3The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized l...
CVE-2024-4159MEDIUM5.3 Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthent...
CVE-2024-2907MEDIUM6.8The AGCA WordPress plugin before 7.2.2 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2024-26926MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: binder: check offset alignment in binder_get_object...
CVE-2024-26925MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release mutex after nft_gc_se...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now