2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11736MEDIUM4.9A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system ...
CVE-2024-11734MEDIUM6.5A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change...
CVE-2024-12006MEDIUM5.3The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2024-13323MEDIUM5.4The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' sho...
CVE-2024-12298MEDIUM5.5We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attac...
CVE-2024-12083MEDIUM6.6Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these ...
CVE-2024-11396MEDIUM5.3The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information ...
CVE-2024-56138MEDIUM4notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specificati...
CVE-2024-46481MEDIUM6.1The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.
CVE-2024-46921MEDIUM6.5An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330,...
CVE-2024-44771MEDIUM6.1BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template functi...
CVE-2024-46920MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le...
CVE-2024-6352MEDIUM4.3A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert
CVE-2024-57488MEDIUM6.5Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter ...
CVE-2024-57487MEDIUM6.5In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a...
CVE-2024-54999MEDIUM6.5MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General ...
CVE-2024-48883MEDIUM4.3An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108...
CVE-2024-46919MEDIUM5.3An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le...
CVE-2024-12211MEDIUM5.4Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
CVE-2024-52937MEDIUM6.7Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2024-52936MEDIUM4.4Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data out...
CVE-2024-52935MEDIUM4.1Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2024-12568MEDIUM4.8The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workfl...
CVE-2024-12567MEDIUM4.8The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form s...
CVE-2024-12566MEDIUM4.8The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form setti...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now