2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25106MEDIUM6.5OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet...
CVE-2024-24494MEDIUM6.1Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via t...
CVE-2024-24115MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated ...
CVE-2024-24215MEDIUM5.3An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configu...
CVE-2024-23764MEDIUM6.7Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, With...
CVE-2024-24834MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – ...
CVE-2024-24878MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Almeida | We...
CVE-2024-24877MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Lt...
CVE-2024-24871MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq B...
CVE-2024-24836MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Audrasjb GDPR Data...
CVE-2024-1312MEDIUM4.7A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same...
CVE-2024-1150MEDIUM5.5Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Mani...
CVE-2024-1149MEDIUM5.5Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software ...
CVE-2024-24885MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lê Văn Toản Woocom...
CVE-2024-24881MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS ...
CVE-2024-24880MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apo...
CVE-2024-24879MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre L...
CVE-2024-24886MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acowebs Product La...
CVE-2024-22464MEDIUM6.8 Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitiv...
CVE-2024-24034MEDIUM6.1Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers t...
CVE-2024-0965MEDIUM5.3The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-0511MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-25146MEDIUM5.3Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 befor...
CVE-2024-25144MEDIUM6.5The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before u...
CVE-2024-1066MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now