2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-21630MEDIUM4.3Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applie...
CVE-2024-22432MEDIUM6.5 Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup dura...
CVE-2024-0879MEDIUM4.3 Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is ...
CVE-2024-23855MEDIUM6.1A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n...
CVE-2024-22099MEDIUM5.5NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows O...
CVE-2024-0625MEDIUM4.8The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notifica...
CVE-2024-0688MEDIUM4.8The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings i...
CVE-2024-0624MEDIUM5.3The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2024-0617MEDIUM5.3The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-23905MEDIUM5.4Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protecti...
CVE-2024-23903MEDIUM5.3Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when ch...
CVE-2024-23902MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier...
CVE-2024-23901MEDIUM6.5Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared w...
CVE-2024-23900MEDIUM4.3Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configur...
CVE-2024-23899MEDIUM6.5Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replace...
CVE-2024-23649MEDIUM6.5Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users ca...
CVE-2024-22720MEDIUM4.8Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
CVE-2024-22229MEDIUM4.3 Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated atta...
CVE-2024-22725MEDIUM6.1Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability w...
CVE-2024-22308MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affec...
CVE-2024-22134MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affe...
CVE-2024-0854MEDIUM5.4URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manag...
CVE-2024-0665MEDIUM6.1The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all...
CVE-2024-22372MEDIUM6.8OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrat...
CVE-2024-22366MEDIUM6.8Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now