2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-44843MEDIUM5.9An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbit...
CVE-2024-42193HIGH8.1HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate valid...
CVE-2024-50960HIGH7.2A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351...
CVE-2024-42200MEDIUM5.4HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validat...
CVE-2024-42189MEDIUM6.5HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an ...
CVE-2024-36842HIGH7.3An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220...
CVE-2024-13177MEDIUM5.2Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the ...
CVE-2024-11084MEDIUM6.3Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whet...
CVE-2024-45712MEDIUM5.4SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be...
CVE-2024-13610MEDIUM4.8The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, ...
CVE-2024-13207MEDIUM4.8The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which ...
CVE-2024-49825MEDIUM4.3IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through ...
CVE-2024-49709MEDIUM4.4Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attack...
CVE-2024-49708MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An ...
CVE-2024-49707MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-49706MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 enco...
CVE-2024-49705MEDIUM6.5Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. A...
CVE-2024-13598MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks....
CVE-2024-13597MEDIUM5.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-10090MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-10089MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An ...
CVE-2024-10088MEDIUM6.1Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-10087MEDIUM5.4Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ...
CVE-2024-9230MEDIUM5.9The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set...
CVE-2024-56406HIGH8.4A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now