2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47586MEDIUM5.3SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously cra...
CVE-2024-42372MEDIUM6.5Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read a...
CVE-2024-11096MEDIUM6.5A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown ...
CVE-2024-11079MEDIUM5.5A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hos...
CVE-2024-51213MEDIUM6.1Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the...
CVE-2024-50601MEDIUM6.1Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to ve...
CVE-2024-23983MEDIUM5.8Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
CVE-2024-51026MEDIUM5.4The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endp...
CVE-2024-52531MEDIUM6.5GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_pars...
CVE-2024-52288MEDIUM5.1libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp...
CVE-2024-51992MEDIUM4.1Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panel...
CVE-2024-51489MEDIUM5.4Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing d...
CVE-2024-51488MEDIUM5.4Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing d...
CVE-2024-51190MEDIUM4.8TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)...
CVE-2024-51189MEDIUM4.8TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)...
CVE-2024-51188MEDIUM4.8TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)...
CVE-2024-51187MEDIUM4.8TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)...
CVE-2024-46965MEDIUM5.4The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows a...
CVE-2024-11078MEDIUM5.4A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vuln...
CVE-2024-10315MEDIUM6.9In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD...
CVE-2024-45087MEDIUM4.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg...
CVE-2024-10917MEDIUM5.3In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapp...
CVE-2024-45088MEDIUM5.4IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticate...
CVE-2024-43439MEDIUM6.1A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting...
CVE-2024-51054MEDIUM4.8A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now