2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7096MEDIUM5.4A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin service...
CVE-2024-53423MEDIUM5.6An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafte...
CVE-2024-22653MEDIUM4.8yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at se...
CVE-2024-57338MEDIUM6.5An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x...
CVE-2024-57337MEDIUM6.5An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.10...
CVE-2024-57336MEDIUM6.5Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unautho...
CVE-2024-47057MEDIUM5.3SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. T...
CVE-2024-47055MEDIUM4.3SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vul...
CVE-2024-47056MEDIUM5.1SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be direct...
CVE-2024-54020MEDIUM4.3A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allo...
CVE-2024-45094MEDIUM5.4IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerabilit...
CVE-2024-11185MEDIUM6.5On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly ...
CVE-2024-49197MEDIUM6.5An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1...
CVE-2024-56193MEDIUM5.1There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local inform...
CVE-2024-47090MEDIUM6.1Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS
CVE-2024-13427MEDIUM6.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-51102MEDIUM4.4PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili...
CVE-2024-51103MEDIUM6.5PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili...
CVE-2024-51099MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medi...
CVE-2024-48704MEDIUM6.1Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter ...
CVE-2024-51108MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL...
CVE-2024-51107MEDIUM4.8Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medi...
CVE-2024-48702MEDIUM5.4PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
CVE-2024-5962MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due...
CVE-2024-7487MEDIUM5.8An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now