2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-51679MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue aff...
CVE-2024-51156MEDIUM4.707FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/...
CVE-2024-40579MEDIUM5.4Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to ...
CVE-2024-39707MEDIUM5.3Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by def...
CVE-2024-49025MEDIUM4.3Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-10396MEDIUM6.5An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, pos...
CVE-2024-52524MEDIUM6.9Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discove...
CVE-2024-4311MEDIUM5.4zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password chan...
CVE-2024-48284MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Reg...
CVE-2024-1682MEDIUM4.3An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This ...
CVE-2024-50836MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management Sy...
CVE-2024-52505MEDIUM5.4matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-apps...
CVE-2024-42188MEDIUM4.6HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update dat...
CVE-2024-7124MEDIUM5.3Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'fil...
CVE-2024-50838MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management ...
CVE-2024-50837MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management ...
CVE-2024-11210MEDIUM5.4A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of th...
CVE-2024-50843MEDIUM5.3A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows...
CVE-2024-50842MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management...
CVE-2024-50841MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Man...
CVE-2024-50840MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management Syste...
CVE-2024-50839MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management...
CVE-2024-11215MEDIUM6.5Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web ser...
CVE-2024-8648MEDIUM6.1An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 ...
CVE-2024-7404MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 pr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now