2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1822MEDIUM6.1A vulnerability classified as problematic has been found in PHPGurukul Tourism Management System 1.0. Affected is an unk...
CVE-2024-26596MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix netdev_priv() dereference before chec...
CVE-2024-26595MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix NULL pointer derefere...
CVE-2024-25629MEDIUM5.5c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such...
CVE-2024-22776MEDIUM4.7Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excludi...
CVE-2024-1362MEDIUM4.3The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-1361MEDIUM4.3The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-1360MEDIUM4.3The Colibri WP theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0...
CVE-2024-1590MEDIUM5.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-0563MEDIUM6.5Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous...
CVE-2024-1779MEDIUM5.3The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-1778MEDIUM5.3The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-1777MEDIUM4.3The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v...
CVE-2024-1784MEDIUM6.6A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown funct...
CVE-2024-26152MEDIUM6.1### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitize...
CVE-2024-25369MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted...
CVE-2024-1749MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Bdtask Bhojon Best Restaurant Management Softwar...
CVE-2024-26151MEDIUM5.4The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a ma...
CVE-2024-26128MEDIUM5.4baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in th...
CVE-2024-25385MEDIUM6.2An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 functi...
CVE-2024-25130MEDIUM6.5Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.9...
CVE-2024-25129MEDIUM5.5The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser u...
CVE-2024-22547MEDIUM4.7WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).
CVE-2024-24817MEDIUM5.3Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discuss...
CVE-2024-26591MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix re-attachment branch in bpf_tracing_prog_a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now