2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35420MEDIUM6.2wac commit 385e1 was discovered to contain a heap overflow.
CVE-2024-35419MEDIUM5.5wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerab...
CVE-2024-35418MEDIUM6.2wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerabi...
CVE-2024-35410MEDIUM6.2wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerabil...
CVE-2024-51157MEDIUM4.707FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/...
CVE-2024-21994MEDIUM4.3StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerab...
CVE-2024-51055MEDIUM6.5An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php componen...
CVE-2024-50810MEDIUM5.4hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps...
CVE-2024-44765MEDIUM6.5An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4...
CVE-2024-9841MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcS...
CVE-2024-51032MEDIUM5.4A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allo...
CVE-2024-51031MEDIUM5.4A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remo...
CVE-2024-51030MEDIUM6.5A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows r...
CVE-2024-40240MEDIUM6.8An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker t...
CVE-2024-40239MEDIUM6.8An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate atta...
CVE-2024-46948MEDIUM4.3Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
CVE-2024-46947MEDIUM6.5Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.
CVE-2024-50378MEDIUM4.9Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensiti...
CVE-2024-10325MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG...
CVE-2024-10187MEDIUM5.4The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo...
CVE-2024-10269MEDIUM5.4The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in ...
CVE-2024-50210MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: posix-clock: posix-clock: Fix unbalanced locking in...
CVE-2024-50208MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a bug while setting up Level-2 PB...
CVE-2024-50207MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix reader locking when changing the s...
CVE-2024-50206MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix memory corruption d...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now