2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-28156MEDIUM5.4Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resultin...
CVE-2024-28155MEDIUM4.3Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attac...
CVE-2024-28154MEDIUM6.5Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in...
CVE-2024-28153MEDIUM5.4Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check rep...
CVE-2024-28152MEDIUM6.3In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discove...
CVE-2024-28151MEDIUM4.3Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recre...
CVE-2024-28150MEDIUM4.7Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as p...
CVE-2024-28149MEDIUM6.5Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers wi...
CVE-2024-20346MEDIUM5.4A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remo...
CVE-2024-20345MEDIUM6.5A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote at...
CVE-2024-20336MEDIUM6.5A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allo...
CVE-2024-20335MEDIUM6.5A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs coul...
CVE-2024-20301MEDIUM6.2A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to...
CVE-2024-20292MEDIUM5.5A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authentica...
CVE-2024-25103MEDIUM6.3This vulnerability exists in AppSamvid software due to the usage of vulnerable and outdated components. An attacker with...
CVE-2024-2211MEDIUM6.1Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacke...
CVE-2024-26627MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: core: Move scsi_host_busy() out of host lock ...
CVE-2024-26626MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packet...
CVE-2024-26623MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq ...
CVE-2024-1989MEDIUM5.4The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-1771MEDIUM4.3The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th...
CVE-2024-1760MEDIUM4.7The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cro...
CVE-2024-27278MEDIUM5.4OpenPNE Plugin "opTimelinePlugin" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which us...
CVE-2024-24785MEDIUM5.4If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-...
CVE-2024-24783MEDIUM5.9Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.V...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now