2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-52612MEDIUM4.8SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient ...
CVE-2024-45718MEDIUM4.6Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a l...
CVE-2024-28989MEDIUM5.5SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive in...
CVE-2024-13570MEDIUM6.1The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-13544MEDIUM4.8The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privile...
CVE-2024-13543MEDIUM6.1The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-12599MEDIUM6.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-57178MEDIUM5.9An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' pa...
CVE-2024-54658MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, mac...
CVE-2024-46437MEDIUM6.5A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unau...
CVE-2024-46430MEDIUM6.5Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web manageme...
CVE-2024-42513MEDIUM5.3Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application...
CVE-2024-13010MEDIUM6.1The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,...
CVE-2024-10649MEDIUM6.1wandb/openui latest commit c945bb859979659add5f490a874140ad17c56a5d contains a vulnerability where unauthenticated endpo...
CVE-2024-57409MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers ...
CVE-2024-48170MEDIUM5.4PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the...
CVE-2024-57950MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Initialize denominator defaults to...
CVE-2024-12243MEDIUM5.3A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libta...
CVE-2024-12133MEDIUM5.3A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements ...
CVE-2024-11831MEDIUM5.4A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not ...
CVE-2024-8685MEDIUM4.3Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could...
CVE-2024-57949MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_...
CVE-2024-54176MEDIUM6.5IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 thro...
CVE-2024-13850MEDIUM4.8The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a...
CVE-2024-55630MEDIUM5.5Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now