2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1892MEDIUM6.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy proj...
CVE-2024-26302MEDIUM4.8A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti...
CVE-2024-26301MEDIUM6.5A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti...
CVE-2024-26300MEDIUM4.8A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to condu...
CVE-2024-26542MEDIUM6.1Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attacke...
CVE-2024-26299MEDIUM4.8A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at...
CVE-2024-25841MEDIUM5.9In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated cust...
CVE-2024-21742MEDIUM5.3Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. Thi...
CVE-2024-1924MEDIUM5.3A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affect...
CVE-2024-26144MEDIUM5.3Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information lea...
CVE-2024-26143MEDIUM6.1Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action...
CVE-2024-25399MEDIUM6.1Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.
CVE-2024-1922MEDIUM5.4A vulnerability has been found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this v...
CVE-2024-1919MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Online Job Portal 1.0. This vulnerability affects ...
CVE-2024-1912MEDIUM4.3The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2024-1910MEDIUM4.3The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2024-1909MEDIUM4.3The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2024-1907MEDIUM4.3The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2024-1906MEDIUM4.3The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2024-1653MEDIUM4.3The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-1652MEDIUM4.3The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-1650MEDIUM4.3The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-1649MEDIUM4.3The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-1106MEDIUM6.1The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-0855MEDIUM5.3The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now