2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-30147MEDIUM6.1Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
CVE-2024-30114MEDIUM5.4Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
CVE-2024-30113MEDIUM5.4Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the...
CVE-2024-30148MEDIUM4.1Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's file...
CVE-2024-13307MEDIUM5.3The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of d...
CVE-2024-12244MEDIUM4.3An issue has been discovered in access controls could allow users to view certain restricted project information even wh...
CVE-2024-22351MEDIUM6.3IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user ...
CVE-2024-58251LOW2.5In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI t...
CVE-2024-47829MEDIUM6.5pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shorten...
CVE-2024-10306MEDIUM5.4A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <L...
CVE-2024-53569MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System...
CVE-2024-53568MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4...
CVE-2024-33452HIGH7.7An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling v...
CVE-2024-46546HIGH7.3NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formF...
CVE-2024-40446CRITICAL9.8An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script
CVE-2024-40445HIGH7.3A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read ...
CVE-2024-11299HIGH7.5The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2024-13569HIGH7.1The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-46899HIGH7.1Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia...
CVE-2024-58250CRITICAL9.3The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
CVE-2024-57394HIGH8.8The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore ...
CVE-2024-12543MEDIUM5.9User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows...
CVE-2024-42699MEDIUM6.5Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to i...
CVE-2024-12863MEDIUM5.6Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malic...
CVE-2024-12862MEDIUM5.5Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now