2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-44905MEDIUM6.5go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
CVE-2024-9512MEDIUM5.9An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prio...
CVE-2024-35295MEDIUM6.1A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manu...
CVE-2024-8270MEDIUM5.5The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Contr...
CVE-2024-41505MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section...
CVE-2024-41504MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportuni...
CVE-2024-41503MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) insid...
CVE-2024-41502MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (o...
CVE-2024-37396MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users t...
CVE-2024-37395MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated us...
CVE-2024-37394MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users ...
CVE-2024-57189MEDIUM5.4In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerabili...
CVE-2024-57186MEDIUM5.4In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerabili...
CVE-2024-54019MEDIUM6.5A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 thr...
CVE-2024-50568MEDIUM5.9A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 thro...
CVE-2024-50562MEDIUM4.8An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve...
CVE-2024-45329MEDIUM4.3A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,...
CVE-2024-32119MEDIUM4.8An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an u...
CVE-2024-41797MEDIUM5.3A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK53...
CVE-2024-40625MEDIUM4.9GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspace...
CVE-2024-47081MEDIUM5.3Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to...
CVE-2024-46452MEDIUM6.1A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b a...
CVE-2024-9994MEDIUM5.4The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-9993MEDIUM5.4The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-56805MEDIUM5.4A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now