2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-27927MEDIUM6.5RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to us...
CVE-2024-27926MEDIUM6.1RSSHub is an open source RSS feed generator. Starting in version 1.0.0-master.cbbd829 and prior to version 1.0.0-master....
CVE-2024-27916MEDIUM4.3Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRe...
CVE-2024-27626MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists withi...
CVE-2024-27291MEDIUM6.1Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a...
CVE-2024-27290MEDIUM6.1Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, a user could type HTML int...
CVE-2024-27105MEDIUM6.5Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed...
CVE-2024-26196MEDIUM4.3Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
CVE-2024-25811MEDIUM6.5An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
CVE-2024-25359MEDIUM6.6An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of ...
CVE-2024-25167MEDIUM6.1Cross Site Scripting vulnerability in eblog v1.0 allows a remote attacker to execute arbitrary code via a crafted script...
CVE-2024-24818MEDIUM5.9EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "P...
CVE-2024-24110MEDIUM6.5SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET r...
CVE-2024-24028MEDIUM5.9Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information...
CVE-2024-22352MEDIUM5.5IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a loc...
CVE-2024-1908MEDIUM6.5An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us...
CVE-2024-1503MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2024-1502MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due...
CVE-2024-1450MEDIUM5.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco...
CVE-2024-1326MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all v...
CVE-2024-1278MEDIUM5.4The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-1214MEDIUM4.3The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2024-1213MEDIUM4.3The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2024-1142MEDIUM5.4Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files...
CVE-2024-0966MEDIUM5.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now