2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-24488MEDIUM5.5An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive informatio...
CVE-2024-23769MEDIUM5.5Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacke...
CVE-2024-24823MEDIUM4.4Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, re...
CVE-2024-24816MEDIUM6.1CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability...
CVE-2024-24706MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Forum One WP-CFM wp-cfm.This issue affects WP-CFM: from n/a through 1...
CVE-2024-23806MEDIUM5.3Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device ...
CVE-2024-24815MEDIUM6.1CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been disc...
CVE-2024-25145MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 ...
CVE-2024-25143MEDIUM6.5The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3...
CVE-2024-24812MEDIUM5.4Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrate...
CVE-2024-24771MEDIUM5.9Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-e...
CVE-2024-24131MEDIUM6.1SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the comp...
CVE-2024-24130MEDIUM6.1Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability vi...
CVE-2024-1110MEDIUM5.3The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-1109MEDIUM5.3The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil...
CVE-2024-1079MEDIUM5.3The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th...
CVE-2024-1078MEDIUM4.3The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-0977MEDIUM5.4The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerabl...
CVE-2024-1055MEDIUM5.4The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored...
CVE-2024-1037MEDIUM6.1The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2024-0256MEDIUM5.4The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Se...
CVE-2024-23447MEDIUM6.5An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions ...
CVE-2024-23446MEDIUM6.5An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DL...
CVE-2024-0849MEDIUM5Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to ...
CVE-2024-1269MEDIUM6.1A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulne...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now