2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-41503MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) insid...
CVE-2024-41502MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (o...
CVE-2024-37396MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users t...
CVE-2024-37395MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated us...
CVE-2024-37394MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users ...
CVE-2024-57189MEDIUM5.4In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerabili...
CVE-2024-57186MEDIUM5.4In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerabili...
CVE-2024-54019MEDIUM6.5A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 thr...
CVE-2024-50568MEDIUM5.9A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 thro...
CVE-2024-50562MEDIUM4.8An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve...
CVE-2024-45329MEDIUM4.3A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,...
CVE-2024-32119MEDIUM4.8An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an u...
CVE-2024-41797MEDIUM5.3A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK53...
CVE-2024-40625MEDIUM4.9GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspace...
CVE-2024-47081MEDIUM5.3Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to...
CVE-2024-46452MEDIUM6.1A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b a...
CVE-2024-9994MEDIUM5.4The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-9993MEDIUM5.4The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-56805MEDIUM5.4A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vu...
CVE-2024-50406MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability c...
CVE-2024-13087MEDIUM6.7A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have ...
CVE-2024-58114MEDIUM4Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnera...
CVE-2024-46941MEDIUM4.8SystemUI has an incorrect component protection setting, which allows access to specific information.
CVE-2024-56343MEDIUM6.5IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a speci...
CVE-2024-56342MEDIUM5.3IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now