2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57773MEDIUM4.8A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 ...
CVE-2024-57772MEDIUM4.8A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 ...
CVE-2024-57771MEDIUM4.8A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allow...
CVE-2024-41746MEDIUM6.1IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allo...
CVE-2024-57161MEDIUM4.307FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit...
CVE-2024-57160MEDIUM4.307FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
CVE-2024-13387MEDIUM6.4The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shor...
CVE-2024-13355MEDIUM5.4The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi...
CVE-2024-12615MEDIUM6.5The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX ac...
CVE-2024-12614MEDIUM4.3The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-12427MEDIUM5.3The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c...
CVE-2024-12226MEDIUM6.5In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s...
CVE-2024-11452MEDIUM6.4The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-10789MEDIUM4.3The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-10970MEDIUM5.4The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution i...
CVE-2024-41454MEDIUM6.5An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-...
CVE-2024-41453MEDIUM4.8A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitr...
CVE-2024-39967MEDIUM6.5Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command...
CVE-2024-36751MEDIUM6.5An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL.
CVE-2024-48122MEDIUM6.7Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileg...
CVE-2024-48121MEDIUM6.5The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. Thi...
CVE-2024-54540MEDIUM4.3The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Proc...
CVE-2024-54535MEDIUM4.3A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia ...
CVE-2024-54470MEDIUM4.6A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPad...
CVE-2024-44136MEDIUM4.6This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now