2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53849MEDIUM4.8editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing)....
CVE-2024-43784MEDIUM5.7lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have ...
CVE-2024-11743MEDIUM4.3A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1....
CVE-2024-11742MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management Syst...
CVE-2024-10240MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting...
CVE-2024-53844MEDIUM6.3E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerab...
CVE-2024-53620MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execut...
CVE-2024-53619MEDIUM6.3An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute ...
CVE-2024-53267MEDIUM5.5sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver...
CVE-2024-11668MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17...
CVE-2024-51058MEDIUM6.2Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read a...
CVE-2024-10878MEDIUM6.1The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to...
CVE-2024-53365MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 i...
CVE-2024-52337MEDIUM5.5A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows ...
CVE-2024-9929MEDIUM4.3A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login informati...
CVE-2024-9928MEDIUM5.3A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, thi...
CVE-2024-8236MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-53976MEDIUM5.4Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, maki...
CVE-2024-53975MEDIUM5.4Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to...
CVE-2024-11708MEDIUM6.5Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This...
CVE-2024-11706MEDIUM6.5A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Ut...
CVE-2024-11703MEDIUM5.7On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authenticatio...
CVE-2024-11701MEDIUM4.3The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could hav...
CVE-2024-11696MEDIUM5.4The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature ver...
CVE-2024-11695MEDIUM5.4A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resultin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now