2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-27779MEDIUM6.7An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version...
CVE-2024-42912MEDIUM5.4A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attac...
CVE-2024-9343MEDIUM6.1In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con...
CVE-2024-10032MEDIUM5.4In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con...
CVE-2024-10031MEDIUM5.4In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configur...
CVE-2024-10029MEDIUM6.1In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration ...
CVE-2024-42649MEDIUM6.5NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a ...
CVE-2024-42648MEDIUM6.5NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via ...
CVE-2024-38648MEDIUM5.7A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensit...
CVE-2024-47065MEDIUM6.5Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not...
CVE-2024-37524MEDIUM5.3IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a de...
CVE-2024-36697MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers...
CVE-2024-7650MEDIUM6.3Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Co...
CVE-2024-56468MEDIUM6.5IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service ...
CVE-2024-49784MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AE...
CVE-2024-49783MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If a...
CVE-2024-36357MEDIUM5.6A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potenti...
CVE-2024-36350MEDIUM5.6A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, pot...
CVE-2024-55599MEDIUM5.3An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 an...
CVE-2024-43190MEDIUM5.9IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to ob...
CVE-2024-37658MEDIUM6.1An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bb...
CVE-2024-37657MEDIUM6.1An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs...
CVE-2024-37656MEDIUM6.1An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the in...
CVE-2024-9453MEDIUM6.5A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially c...
CVE-2024-11937MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's link...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now