2024 CVE Vulnerabilities

39,152 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-9654LOW3.7The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T...
CVE-2024-56082LOW3.5ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disab...
CVE-2024-12300LOW3.7The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca...
CVE-2024-10043LOW3.1An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting...
CVE-2024-54493LOW3.3This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2. Privacy indicator...
CVE-2024-54491LOW3.3The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious application may be ...
CVE-2024-54485LOW2.4The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macO...
CVE-2024-53274LOW2Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scrip...
CVE-2024-44290LOW3.3This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18...
CVE-2024-44200LOW3.3This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18...
CVE-2024-11053LOW3.4When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used f...
CVE-2024-55655LOW2.7sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer tha...
CVE-2024-54133LOW2.3Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) v...
CVE-2024-52831LOW3.5Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou...
CVE-2024-43755LOW3.5Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou...
CVE-2024-55550LOW2.7Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local fi...
CVE-2024-47577LOW2.7Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability....
CVE-2024-47576LOW3.3SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Win...
CVE-2024-12174LOW2.7An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged at...
CVE-2024-12057LOW1.8User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a W...
CVE-2024-53947LOW2.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. S...
CVE-2024-50403LOW2.1A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50402LOW2.1A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-48866LOW2.3An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating sys...
CVE-2024-6219LOW3.8Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now