2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39730MEDIUM5.4IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim....
CVE-2024-36347MEDIUM6.4Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri...
CVE-2024-56915MEDIUM6.5Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.
CVE-2024-11584MEDIUM5.3cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grant...
CVE-2024-57708MEDIUM5.7An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __...
CVE-2024-51984MEDIUM6.8An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled ...
CVE-2024-51981MEDIUM5.3An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c...
CVE-2024-51980MEDIUM5.3An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open ...
CVE-2024-51977MEDIUM5.3An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t...
CVE-2024-56916MEDIUM6.1In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) d...
CVE-2024-56918MEDIUM6.1In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authen...
CVE-2024-3511MEDIUM4.3An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned f...
CVE-2024-54172MEDIUM4.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera...
CVE-2024-54183MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera...
CVE-2024-40570MEDIUM6.5SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_data...
CVE-2024-25573MEDIUM6.9Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScrip...
CVE-2024-38825MEDIUM6.4The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate whic...
CVE-2024-55567MEDIUM6.7Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55....
CVE-2024-44906MEDIUM6.5uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/...
CVE-2024-44905MEDIUM6.5go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
CVE-2024-9512MEDIUM5.9An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prio...
CVE-2024-35295MEDIUM6.1A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manu...
CVE-2024-8270MEDIUM5.5The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Contr...
CVE-2024-41505MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section...
CVE-2024-41504MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportuni...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now