2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53619MEDIUM6.3An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute ...
CVE-2024-53267MEDIUM5.5sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver...
CVE-2024-11668MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17...
CVE-2024-51058MEDIUM6.2Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read a...
CVE-2024-10878MEDIUM6.1The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to...
CVE-2024-53365MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 i...
CVE-2024-52337MEDIUM5.5A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows ...
CVE-2024-9929MEDIUM4.3A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login informati...
CVE-2024-9928MEDIUM5.3A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, thi...
CVE-2024-8236MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-53976MEDIUM5.4Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, maki...
CVE-2024-53975MEDIUM5.4Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to...
CVE-2024-11708MEDIUM6.5Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This...
CVE-2024-11706MEDIUM6.5A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Ut...
CVE-2024-11703MEDIUM5.7On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authenticatio...
CVE-2024-11701MEDIUM4.3The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could hav...
CVE-2024-11696MEDIUM5.4The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature ver...
CVE-2024-11695MEDIUM5.4A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resultin...
CVE-2024-11694MEDIUM6.1Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS thr...
CVE-2024-11692MEDIUM4.3An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possib...
CVE-2024-47250MEDIUM5Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to ou...
CVE-2024-47249MEDIUM5Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from control...
CVE-2024-47248MEDIUM6.3Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafte...
CVE-2024-38834MEDIUM4.8VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cl...
CVE-2024-38833MEDIUM5.4VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to em...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now