2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25151MEDIUM5.4The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before se...
CVE-2024-1676MEDIUM5.4Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof se...
CVE-2024-1672MEDIUM5.4Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacke...
CVE-2024-1671MEDIUM6.5Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypa...
CVE-2024-1562MEDIUM5.3The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2024-1501MEDIUM4.7The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-26269MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37...
CVE-2024-26266MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupport...
CVE-2024-25603MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 thr...
CVE-2024-25602MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7...
CVE-2024-25601MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 th...
CVE-2024-25152MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older...
CVE-2024-25147MEDIUM6.1Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsup...
CVE-2024-0407MEDIUM6.5Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, w...
CVE-2024-26140MEDIUM6.1com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5...
CVE-2024-25428MEDIUM6.5SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.
CVE-2024-25631MEDIUM5.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have ena...
CVE-2024-25630MEDIUM5.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are usin...
CVE-2024-25260MEDIUM4elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
CVE-2024-24763MEDIUM6.1JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10....
CVE-2024-25366MEDIUM6.2Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of serv...
CVE-2024-26270MEDIUM5.3The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 u...
CVE-2024-26268MEDIUM5.3User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP...
CVE-2024-25197MEDIUM6.5Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dere...
CVE-2024-1556MEDIUM6.5The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and und...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now