2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47836MEDIUM4.3Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability all...
CVE-2024-45796MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-41128MEDIUM6.6Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions ...
CVE-2024-9143MEDIUM4.3Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial ...
CVE-2024-46606MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to ...
CVE-2024-46605MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to ...
CVE-2024-45072MEDIUM5.5IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when process...
CVE-2024-45071MEDIUM4.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p...
CVE-2024-20512MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) c...
CVE-2024-20462MEDIUM5.5A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter fir...
CVE-2024-20461MEDIUM6A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, ...
CVE-2024-20460MEDIUM6.1A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al...
CVE-2024-20421MEDIUM6.5A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al...
CVE-2024-20280MEDIUM6.3A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file...
CVE-2024-10033MEDIUM6.1A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. Th...
CVE-2024-49265MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SPBooking.com Book...
CVE-2024-29155MEDIUM4.3On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device beco...
CVE-2024-49268MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkam...
CVE-2024-49267MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited ...
CVE-2024-49266MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thimo Grauerholz W...
CVE-2024-48744MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Reco...
CVE-2024-47139MEDIUM6.8A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that...
CVE-2024-49270MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart B...
CVE-2024-49258MEDIUM6.5Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This is...
CVE-2024-49252MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.Thi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now