2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22307MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister L...
CVE-2024-22306MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Boar...
CVE-2024-22302MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ignazio Scimone Al...
CVE-2024-23508MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins PDF Poste...
CVE-2024-23505MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DearHive PDF Viewe...
CVE-2024-23502MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in InfornWeb Posts Li...
CVE-2024-1103MEDIUM5.4A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by ...
CVE-2024-0589MEDIUM5.4Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and e...
CVE-2024-22287MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS)....
CVE-2024-1099MEDIUM5.4A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFil...
CVE-2024-23170MEDIUM5.5An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA priva...
CVE-2024-0836MEDIUM4.3The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-22236MEDIUM5.5In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1....
CVE-2024-0914MEDIUM5.9A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 pad...
CVE-2024-22569MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a craft...
CVE-2024-23834MEDIUM6.1Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in s...
CVE-2024-24567MEDIUM5.3Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in b...
CVE-2024-24558MEDIUM6.1TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tans...
CVE-2024-24556MEDIUM6.1urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable t...
CVE-2024-23841MEDIUM6.1apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nex...
CVE-2024-21388MEDIUM6.5Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2024-24565MEDIUM6.5CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. Th...
CVE-2024-23840MEDIUM5.5GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a ta...
CVE-2024-23825MEDIUM4.9TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL...
CVE-2024-22200MEDIUM5.3vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now