2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47057MEDIUM5.3SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. T...
CVE-2024-47055MEDIUM4.3SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vul...
CVE-2024-47056MEDIUM5.1SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be direct...
CVE-2024-54020MEDIUM4.3A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allo...
CVE-2024-45094MEDIUM5.4IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerabilit...
CVE-2024-11185MEDIUM6.5On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly ...
CVE-2024-49197MEDIUM6.5An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1...
CVE-2024-56193MEDIUM5.1There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local inform...
CVE-2024-47090MEDIUM6.1Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS
CVE-2024-13427MEDIUM6.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-51102MEDIUM4.4PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili...
CVE-2024-51103MEDIUM6.5PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabili...
CVE-2024-51099MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medi...
CVE-2024-48704MEDIUM6.1Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter ...
CVE-2024-51108MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL...
CVE-2024-51107MEDIUM4.8Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medi...
CVE-2024-48702MEDIUM5.4PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
CVE-2024-5962MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due...
CVE-2024-7487MEDIUM5.8An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows ...
CVE-2024-7103MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7...
CVE-2024-13958MEDIUM4.8Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue a...
CVE-2024-13954MEDIUM6.5Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration too...
CVE-2024-13953MEDIUM6.9Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue a...
CVE-2024-13950MEDIUM6.9Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator cre...
CVE-2024-13949MEDIUM6.9Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now