2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30147 | MEDIUM | 6.1 | 0.2% | Apr 24, 2025 | Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications. |
| CVE-2024-30114 | MEDIUM | 5.4 | 0.2% | Apr 24, 2025 | Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment. |
| CVE-2024-30113 | MEDIUM | 5.4 | 0.2% | Apr 24, 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the... |
| CVE-2024-30148 | MEDIUM | 4.1 | 0.2% | Apr 24, 2025 | Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's file... |
| CVE-2024-13307 | MEDIUM | 5.3 | 0.2% | Apr 24, 2025 | The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of d... |
| CVE-2024-12244 | MEDIUM | 4.3 | 0.3% | Apr 24, 2025 | An issue has been discovered in access controls could allow users to view certain restricted project information even wh... |
| CVE-2024-22351 | MEDIUM | 6.3 | 0.2% | Apr 23, 2025 | IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user ... |
| CVE-2024-58251 | LOW | 2.5 | 0.2% | Apr 23, 2025 | In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI t... |
| CVE-2024-47829 | MEDIUM | 6.5 | 0.2% | Apr 23, 2025 | pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shorten... |
| CVE-2024-10306 | MEDIUM | 5.4 | 0.3% | Apr 23, 2025 | A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <L... |
| CVE-2024-53569 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System... |
| CVE-2024-53568 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4... |
| CVE-2024-33452 | HIGH | 7.7 | 0.7% | Apr 22, 2025 | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling v... |
| CVE-2024-46546 | HIGH | 7.3 | 0.4% | Apr 22, 2025 | NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formF... |
| CVE-2024-40446 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script |
| CVE-2024-40445 | HIGH | 7.3 | 0.6% | Apr 22, 2025 | A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read ... |
| CVE-2024-11299 | HIGH | 7.5 | 0.3% | Apr 22, 2025 | The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2024-13569 | HIGH | 7.1 | 0.5% | Apr 22, 2025 | The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-46899 | HIGH | 7.1 | 0.3% | Apr 22, 2025 | Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia... |
| CVE-2024-58250 | CRITICAL | 9.3 | 0.2% | Apr 22, 2025 | The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges. |
| CVE-2024-57394 | HIGH | 8.8 | 0.5% | Apr 21, 2025 | The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore ... |
| CVE-2024-12543 | MEDIUM | 5.9 | 0.3% | Apr 21, 2025 | User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows... |
| CVE-2024-42699 | MEDIUM | 6.5 | 0.3% | Apr 21, 2025 | Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to i... |
| CVE-2024-12863 | MEDIUM | 5.6 | 0.3% | Apr 21, 2025 | Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malic... |
| CVE-2024-12862 | MEDIUM | 5.5 | 0.2% | Apr 21, 2025 | Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now