2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-31230MEDIUM5.3Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affec...
CVE-2024-3570MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm rep...
CVE-2024-3388MEDIUM5A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to ...
CVE-2024-3387MEDIUM5.9A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a me...
CVE-2024-3386MEDIUM5.3An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclus...
CVE-2024-31342MEDIUM6.5Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Ex...
CVE-2024-1625MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allow...
CVE-2024-1602MEDIUM6.1parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The ...
CVE-2024-31874MEDIUM5.5IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow ...
CVE-2024-31353MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slidesh...
CVE-2024-31302MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue aff...
CVE-2024-31297MEDIUM5.3Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce:...
CVE-2024-31287MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Librar...
CVE-2024-31282MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Buil...
CVE-2024-31278MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in Leap13 Premium Addons for Elementor premium-addons-fo...
CVE-2024-31253MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAu...
CVE-2024-23735MEDIUM6.1Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in ...
CVE-2024-23734MEDIUM5.2Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify ...
CVE-2024-3567MEDIUM5.5A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c...
CVE-2024-29296MEDIUM5.3A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process,...
CVE-2024-27477MEDIUM6.1In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality...
CVE-2024-27476MEDIUM4.7Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.
CVE-2024-3448MEDIUM5Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?act...
CVE-2024-2731MEDIUM5.4Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages ...
CVE-2024-2730MEDIUM5.3Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated use...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now