2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13394MEDIUM6.4The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortco...
CVE-2024-13334MEDIUM6.1The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter ...
CVE-2024-57760MEDIUM6.5JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CG...
CVE-2024-53277MEDIUM5.4Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HT...
CVE-2024-47605MEDIUM5.4silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functional...
CVE-2024-50861MEDIUM6.1The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod...
CVE-2024-50859MEDIUM4.8The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly forma...
CVE-2024-50857MEDIUM4.8The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en...
CVE-2024-45102MEDIUM6.8A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their ...
CVE-2024-10254MEDIUM4.7A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could al...
CVE-2024-10253MEDIUM4.7A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a loc...
CVE-2024-55945MEDIUM6.5TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55923MEDIUM4.3TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55922MEDIUM5.4TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55920MEDIUM4.3TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55894MEDIUM5.4TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55893MEDIUM4.3TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55892MEDIUM6.1TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse e...
CVE-2024-55891MEDIUM5.3TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has ...
CVE-2024-50349MEDIUM4.7Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2024-12747MEDIUM5.6A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rs...
CVE-2024-12086MEDIUM6.8A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's mach...
CVE-2024-53563MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to ex...
CVE-2024-52898MEDIUM6.2IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a ...
CVE-2024-45627MEDIUM5.9In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql J...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now