2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13069MEDIUM5.4A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected...
CVE-2024-12105MEDIUM6.5In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that c...
CVE-2024-56229MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a thro...
CVE-2024-56222MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Requ...
CVE-2024-56218MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dyn...
CVE-2024-56216MEDIUM6.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-13067MEDIUM5.3A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects so...
CVE-2024-13058MEDIUM4.8An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could pote...
CVE-2024-13042MEDIUM5.3A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been clas...
CVE-2024-11946MEDIUM6.5iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This...
CVE-2024-46542MEDIUM6.5Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks.
CVE-2024-56734MEDIUM6.1Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verif...
CVE-2024-56733MEDIUM5.7Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has bee...
CVE-2024-56517MEDIUM5.3LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 con...
CVE-2024-56516MEDIUM6.9free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API f...
CVE-2024-52294MEDIUM4.3Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR...
CVE-2024-12754MEDIUM5.5AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensi...
CVE-2024-50702MEDIUM5.3TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an adminis...
CVE-2024-50701MEDIUM4.3TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a...
CVE-2024-12993MEDIUM4.8Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An atta...
CVE-2024-47923MEDIUM5.3Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-47918MEDIUM6.1Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-13033MEDIUM6.1A vulnerability, which was classified as problematic, has been found in code-projects Chat System 1.0. Affected by this ...
CVE-2024-13032MEDIUM4.9A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. Affected by this vulnerability ...
CVE-2024-13031MEDIUM4.8A vulnerability classified as problematic has been found in Antabot White-Jotter up to 0.2.2. Affected is an unknown fun...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now