2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-21853MEDIUM5.7Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors m...
CVE-2024-21808MEDIUM4.2Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to pote...
CVE-2024-21783MEDIUM4.8Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially ena...
CVE-2024-11193MEDIUM6.5An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext...
CVE-2024-42834MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC...
CVE-2024-40443MEDIUM4.3SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to...
CVE-2024-49379MEDIUM5.3Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected...
CVE-2024-43090MEDIUM5In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to l...
CVE-2024-43086MEDIUM5.5In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a thir...
CVE-2024-43084MEDIUM5.5In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to ...
CVE-2024-43083MEDIUM5.5In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion....
CVE-2024-43082MEDIUM5.5In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy....
CVE-2024-9476MEDIUM5.1A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to re...
CVE-2024-52292MEDIUM6.5Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions o...
CVE-2024-45594MEDIUM5.4Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subj...
CVE-2024-8049MEDIUM6.5In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with un...
CVE-2024-7295MEDIUM6.2In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an...
CVE-2024-52305MEDIUM4.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exi...
CVE-2024-50969MEDIUM6.1A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote atta...
CVE-2024-11175MEDIUM4.8A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown proces...
CVE-2024-9477MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air...
CVE-2024-49505MEDIUM6.1A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumblew...
CVE-2024-48900MEDIUM4.3A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipi...
CVE-2024-11165MEDIUM5.7An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in ...
CVE-2024-11159MEDIUM4.3Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects T...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now