2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-50841MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Man...
CVE-2024-50840MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management Syste...
CVE-2024-50839MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management...
CVE-2024-11215MEDIUM6.5Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web ser...
CVE-2024-8648MEDIUM6.1An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 ...
CVE-2024-7404MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 pr...
CVE-2024-11207MEDIUM5.4A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unk...
CVE-2024-10978MEDIUM4.2Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows ...
CVE-2024-10976MEDIUM5.4Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows fro...
CVE-2024-45642MEDIUM5.3IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb...
CVE-2024-45099MEDIUM4.8IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb...
CVE-2024-3447MEDIUM6A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_co...
CVE-2024-8180MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17....
CVE-2024-5920MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Pan...
CVE-2024-5919MEDIUM6.5A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authent...
CVE-2024-5918MEDIUM4.3An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a...
CVE-2024-5917MEDIUM4.9A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use...
CVE-2024-47914MEDIUM4.5VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)
CVE-2024-2552MEDIUM6A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass...
CVE-2024-7787MEDIUM5.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Compute...
CVE-2024-10146MEDIUM5.4The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it ba...
CVE-2024-5083MEDIUM5.1A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus...
CVE-2024-40410MEDIUM4.8Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for ...
CVE-2024-51027MEDIUM6.5Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the prov...
CVE-2024-50956MEDIUM6.5A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now