2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-49722MEDIUM5.5In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy....
CVE-2024-51423MEDIUM6.1Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execut...
CVE-2024-48705MEDIUM6.5Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication ...
CVE-2024-12974MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Pr...
CVE-2024-12973MEDIUM4.7Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsi...
CVE-2024-12972MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Oc...
CVE-2024-12924MEDIUM6.3URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing...
CVE-2024-12914MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR...
CVE-2024-12923MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user ...
CVE-2024-13987MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Se...
CVE-2024-54568MEDIUM4.3The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously ...
CVE-2024-54554MEDIUM5.5This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ab...
CVE-2024-48908MEDIUM6.9lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there i...
CVE-2024-49790MEDIUM5.4IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an ...
CVE-2024-9648MEDIUM6.1The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i...
CVE-2024-49740MEDIUM5.5In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of ser...
CVE-2024-47192MEDIUM5.3An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker ...
CVE-2024-35203MEDIUM6.1Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part o...
CVE-2024-45753MEDIUM6.1In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value ...
CVE-2024-8860MEDIUM4.3The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-46413MEDIUM5.1Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild....
CVE-2024-46412MEDIUM6.5Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a cra...
CVE-2024-39923MEDIUM6.1An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer lin...
CVE-2024-58239MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us...
CVE-2024-39954MEDIUM6.3CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now