2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-52801MEDIUM5.3sftpgo is a full-featured and highly configurable event-driven file transfer solution. Server protocols: SFTP, HTTP/S, F...
CVE-2024-52003MEDIUM6.1Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows...
CVE-2024-36616MEDIUM6.5An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of ...
CVE-2024-36615MEDIUM5.9FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding para...
CVE-2024-36624MEDIUM5.4Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.
CVE-2024-36621MEDIUM6.5moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could...
CVE-2024-36620MEDIUM6.5moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-36618MEDIUM6.2FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, po...
CVE-2024-36617MEDIUM6.2FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
CVE-2024-47193MEDIUM5.5WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow ...
CVE-2024-36626MEDIUM5.3In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.
CVE-2024-36625MEDIUM5.4Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.
CVE-2024-36619MEDIUM5.3FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow w...
CVE-2024-35369MEDIUM5.5In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists d...
CVE-2024-11990MEDIUM4.6A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript co...
CVE-2024-47094MEDIUM5.5Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL...
CVE-2024-9044MEDIUM4.6A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across mu...
CVE-2024-11014MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 u...
CVE-2024-39162MEDIUM6.1pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported ...
CVE-2024-10980MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress ...
CVE-2024-10704MEDIUM4.8The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which coul...
CVE-2024-45495MEDIUM4.3MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.
CVE-2024-35451MEDIUM4.8LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.
CVE-2024-54123MEDIUM6.1Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text...
CVE-2024-11971MEDIUM5.4A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerab...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now