2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-52001MEDIUM4.3Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access for...
CVE-2024-52000MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site ...
CVE-2024-35427MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser....
CVE-2024-35425MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_funct...
CVE-2024-35424MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser....
CVE-2024-35421MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser...
CVE-2024-35420MEDIUM6.2wac commit 385e1 was discovered to contain a heap overflow.
CVE-2024-35419MEDIUM5.5wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerab...
CVE-2024-35418MEDIUM6.2wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerabi...
CVE-2024-35410MEDIUM6.2wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerabil...
CVE-2024-51157MEDIUM4.707FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/...
CVE-2024-21994MEDIUM4.3StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerab...
CVE-2024-51055MEDIUM6.5An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php componen...
CVE-2024-50810MEDIUM5.4hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps...
CVE-2024-44765MEDIUM6.5An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4...
CVE-2024-9841MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcS...
CVE-2024-51032MEDIUM5.4A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allo...
CVE-2024-51031MEDIUM5.4A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remo...
CVE-2024-51030MEDIUM6.5A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows r...
CVE-2024-40240MEDIUM6.8An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker t...
CVE-2024-40239MEDIUM6.8An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate atta...
CVE-2024-46948MEDIUM4.3Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
CVE-2024-46947MEDIUM6.5Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.
CVE-2024-50378MEDIUM4.9Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensiti...
CVE-2024-10325MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now