2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57680MEDIUM5.3An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth...
CVE-2024-57679MEDIUM6.5An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthe...
CVE-2024-57678MEDIUM6.5An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated ...
CVE-2024-57677MEDIUM6.5An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a...
CVE-2024-57676MEDIUM6.5An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth...
CVE-2024-52594MEDIUM4.3Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery,...
CVE-2024-57776MEDIUM4.6A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allow...
CVE-2024-57774MEDIUM4.8A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01....
CVE-2024-57773MEDIUM4.8A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 ...
CVE-2024-57772MEDIUM4.8A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 ...
CVE-2024-57771MEDIUM4.8A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allow...
CVE-2024-41746MEDIUM6.1IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allo...
CVE-2024-57161MEDIUM4.307FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit...
CVE-2024-57160MEDIUM4.307FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
CVE-2024-13387MEDIUM6.4The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shor...
CVE-2024-13355MEDIUM5.4The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi...
CVE-2024-12615MEDIUM6.5The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX ac...
CVE-2024-12614MEDIUM4.3The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-12427MEDIUM5.3The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c...
CVE-2024-12226MEDIUM6.5In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s...
CVE-2024-11452MEDIUM6.4The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-10789MEDIUM4.3The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-10970MEDIUM5.4The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution i...
CVE-2024-41454MEDIUM6.5An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-...
CVE-2024-41453MEDIUM4.8A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now