2024 CVE Vulnerabilities

39,220 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8881MEDIUM6.8A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version ...
CVE-2024-49393MEDIUM6.5In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker tha...
CVE-2024-11097MEDIUM5.5A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. Thi...
CVE-2024-47593MEDIUM4.3SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the serv...
CVE-2024-47592MEDIUM5.3SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the...
CVE-2024-47588MEDIUM4.7In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors,...
CVE-2024-47586MEDIUM5.3SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously cra...
CVE-2024-42372MEDIUM6.5Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read a...
CVE-2024-11096MEDIUM6.5A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown ...
CVE-2024-11079MEDIUM5.5A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hos...
CVE-2024-51213MEDIUM6.1Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the...
CVE-2024-50601MEDIUM6.1Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to ve...
CVE-2024-23983MEDIUM5.8Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
CVE-2024-51026MEDIUM5.4The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endp...
CVE-2024-52531MEDIUM6.5GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_pars...
CVE-2024-52288MEDIUM5.1libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp...
CVE-2024-51992MEDIUM4.1Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panel...
CVE-2024-51489MEDIUM5.4Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing d...
CVE-2024-51488MEDIUM5.4Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing d...
CVE-2024-51190MEDIUM4.8TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)...
CVE-2024-51189MEDIUM4.8TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)...
CVE-2024-51188MEDIUM4.8TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)...
CVE-2024-51187MEDIUM4.8TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)...
CVE-2024-46965MEDIUM5.4The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows a...
CVE-2024-11078MEDIUM5.4A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vuln...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now