2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-26590MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: erofs: fix inconsistent per-file compression format...
CVE-2024-26587MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: netdevsim: don't try to destroy PHC on VFs PH...
CVE-2024-26586MEDIUM6.7In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption Whe...
CVE-2024-25828MEDIUM4.9cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.
CVE-2024-26284MEDIUM6.1Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, ...
CVE-2024-26281MEDIUM4.7Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the cur...
CVE-2024-26445MEDIUM6.1flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_pla...
CVE-2024-26351MEDIUM6.1flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_pla...
CVE-2024-26349MEDIUM4.3flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_tra...
CVE-2024-25876MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitr...
CVE-2024-25875MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitr...
CVE-2024-25874MEDIUM5.4A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to exec...
CVE-2024-25873MEDIUM5.4Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote m...
CVE-2024-26578MEDIUM5.9Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ...
CVE-2024-23349MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This...
CVE-2024-26491MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CM...
CVE-2024-26490MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execut...
CVE-2024-26489MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allo...
CVE-2024-1053MEDIUM4.3The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...
CVE-2024-0903MEDIUM6.1The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera...
CVE-2024-26484MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers...
CVE-2024-26481MEDIUM4.7Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.
CVE-2024-25801MEDIUM6.1SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload i...
CVE-2024-1525MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions start...
CVE-2024-0861MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now