2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-49632MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Senthil Vel CWD 3D...
CVE-2024-47640MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp ...
CVE-2024-10226MEDIUM5.4The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcod...
CVE-2024-8143MEDIUM4.3In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authen...
CVE-2024-7473MEDIUM6.5An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions ...
CVE-2024-7472MEDIUM6.5lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-ve...
CVE-2024-7010MEDIUM5.9mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to c...
CVE-2024-6673MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` fi...
CVE-2024-51181MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code ...
CVE-2024-51180MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGurukul IFSC Code Finder P...
CVE-2024-49645MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilias Gomatos Affi...
CVE-2024-49643MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fifthsegment White...
CVE-2024-49641MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tidaweb Tida URL S...
CVE-2024-49640MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AmaderCode Lab ACL...
CVE-2024-49639MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Stoever Mon...
CVE-2024-49638MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ventureharbour Ris...
CVE-2024-49637MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foxskav Bet WC 201...
CVE-2024-49636MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woracal Agile Vide...
CVE-2024-49635MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manjurul.cis Banne...
CVE-2024-10474MEDIUM6.5Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in link...
CVE-2024-10468MEDIUM5.3Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. ...
CVE-2024-10465MEDIUM6.5A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox...
CVE-2024-10464MEDIUM6.5Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the brows...
CVE-2024-10463MEDIUM6.5Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefo...
CVE-2024-10462MEDIUM6.5Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox <...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now