2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47882MEDIUM6.1OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went...
CVE-2024-47880MEDIUM6.9OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command ca...
CVE-2024-47878MEDIUM6.1OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/author...
CVE-2024-45259MEDIUM6.5An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By inte...
CVE-2024-47173MEDIUM5.5Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version ...
CVE-2024-46998MEDIUM5.4baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Ed...
CVE-2024-46996MEDIUM5.4baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Bl...
CVE-2024-46995MEDIUM6.1baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 4...
CVE-2024-46994MEDIUM5.4baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog p...
CVE-2024-48442MEDIUM6.5Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2...
CVE-2024-38314MEDIUM5.9IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-...
CVE-2024-9692MEDIUM6.9VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attack...
CVE-2024-48540MEDIUM6.2Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code a...
CVE-2024-44205MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 an...
CVE-2024-44185MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma...
CVE-2024-44141MEDIUM6.8The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to...
CVE-2024-40810MEDIUM5.5An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An ...
CVE-2024-45031MEDIUM6.1When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made i...
CVE-2024-49702MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred ...
CVE-2024-49696MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gall...
CVE-2024-49695MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP ...
CVE-2024-49693MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega...
CVE-2024-10332MEDIUM6.1A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacke...
CVE-2024-10180MEDIUM5.4The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-8959MEDIUM6.4The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now