2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-26559MEDIUM5.3An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.
CVE-2024-25579MEDIUM6.8OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrat...
CVE-2024-22532MEDIUM6.5Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service v...
CVE-2024-21798MEDIUM4.8ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user co...
CVE-2024-26450MEDIUM5.4An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit invol...
CVE-2024-25868MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attack...
CVE-2024-1972MEDIUM5.4A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue ...
CVE-2024-27285MEDIUM6.1YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to...
CVE-2024-25435MEDIUM6.1A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scri...
CVE-2024-25202MEDIUM6.1Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attacke...
CVE-2024-27103MEDIUM6.1Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search resu...
CVE-2024-0560MEDIUM4.3A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is us...
CVE-2024-24705MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a th...
CVE-2024-1965MEDIUM5.3Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could ...
CVE-2024-1808MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-26016MEDIUM5.4A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then ...
CVE-2024-24779MEDIUM6.5Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows fo...
CVE-2024-24773MEDIUM6.5Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization ...
CVE-2024-24772MEDIUM4.3A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information ...
CVE-2024-1636MEDIUM5.4Potential Cross-Site Scripting (XSS) in the page editing area.
CVE-2024-1632MEDIUM6.5Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrati...
CVE-2024-27315MEDIUM4.3An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially cr...
CVE-2024-1861MEDIUM4.3The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v...
CVE-2024-1860MEDIUM5.3The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v...
CVE-2024-1719MEDIUM4.3The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now