2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47801MEDIUM6.1Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scr...
CVE-2024-47549MEDIUM6.1Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of uninte...
CVE-2024-45842MEDIUM5.3Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability....
CVE-2024-10148MEDIUM5.4The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in...
CVE-2024-9109MEDIUM4.3The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modificat...
CVE-2024-9686MEDIUM5.3The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a mis...
CVE-2024-10355MEDIUM4.9A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0....
CVE-2024-10354MEDIUM4.9A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this...
CVE-2024-49762MEDIUM4.6Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the ...
CVE-2024-49760MEDIUM5.3OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter...
CVE-2024-49750MEDIUM5.5The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak...
CVE-2024-49358MEDIUM5.3ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all ...
CVE-2024-10348MEDIUM5.4A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problemat...
CVE-2024-48932MEDIUM5.3ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, ...
CVE-2024-48426MEDIUM6.2A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz t...
CVE-2024-48425MEDIUM5.5A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the...
CVE-2024-48424MEDIUM5.5A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp...
CVE-2024-47882MEDIUM6.1OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went...
CVE-2024-47880MEDIUM6.9OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command ca...
CVE-2024-47878MEDIUM6.1OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/author...
CVE-2024-45259MEDIUM6.5An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By inte...
CVE-2024-47173MEDIUM5.5Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version ...
CVE-2024-46998MEDIUM5.4baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Ed...
CVE-2024-46996MEDIUM5.4baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Bl...
CVE-2024-46995MEDIUM6.1baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 4...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now