2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-28782MEDIUM6.5IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores u...
CVE-2024-28589MEDIUM6.7An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attac...
CVE-2024-24506MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attacke...
CVE-2024-31008MEDIUM6.5An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive inf...
CVE-2024-2322MEDIUM6.8The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, w...
CVE-2024-31013MEDIUM6.1Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via ...
CVE-2024-31009MEDIUM6.5SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter...
CVE-2024-3162MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attri...
CVE-2024-28836MEDIUM5.4An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall...
CVE-2024-28755MEDIUM6.5An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset...
CVE-2024-28219MEDIUM5.9In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
CVE-2024-26495MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbi...
CVE-2024-1327MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widge...
CVE-2024-3225MEDIUM6.5A vulnerability was found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this ...
CVE-2024-3218MEDIUM5.4A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System ...
CVE-2024-3248MEDIUM5.5In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.
CVE-2024-3247MEDIUM5.5In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.
CVE-2024-3202MEDIUM5.9A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue aff...
CVE-2024-30370MEDIUM4.3RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The...
CVE-2024-30363MEDIUM5.5Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem...
CVE-2024-25075MEDIUM5.1An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotification...
CVE-2024-29834MEDIUM6.4This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on ...
CVE-2024-30532MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects ...
CVE-2024-30531MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from ...
CVE-2024-24888MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This iss...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now