2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53985MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53989MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-49581MEDIUM6.5Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could ...
CVE-2024-5890MEDIUM5.1ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability cou...
CVE-2024-53617MEDIUM4.8A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via upl...
CVE-2024-53566MEDIUM5.5An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows...
CVE-2024-53364MEDIUM5.4A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php....
CVE-2024-53259MEDIUM6.5quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet...
CVE-2024-53984MEDIUM4.3Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, ...
CVE-2024-53459MEDIUM5.4Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.
CVE-2024-8785MEDIUM5.3In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create ...
CVE-2024-38827MEDIUM4.8The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially r...
CVE-2024-53784MEDIUM4.3Missing Authorization vulnerability in E-goi Smart Marketing SMS and Newsletters Forms smart-marketing-for-wp allows Exp...
CVE-2024-53775MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in benmoreassynt DancePress (TRWA) dancepress-trwa allows Cross Site Req...
CVE-2024-53761MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in P Roy WP Revisions Manager wp-revisions-manager allows Cross Site Req...
CVE-2024-53741MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simp...
CVE-2024-53721MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stachethemes Advan...
CVE-2024-53709MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generi...
CVE-2024-53708MEDIUM5.3Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained ...
CVE-2024-53707MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ahmeti Ahmeti Wp Güzel Sözler ahmeti-wp-guzel-sozler allows Cross Sit...
CVE-2024-53124MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: net: fix data-races around sk->sk_forward_alloc Sy...
CVE-2024-53123MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mptcp: error out earlier on disconnect Eric report...
CVE-2024-53122MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mptcp: cope racing subflow creation in mptcp_rcv_sp...
CVE-2024-53121MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, lock FTE when checking if active The...
CVE-2024-53120MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: CT: Fix null-ptr-deref in add rule err f...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now