2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47829 | MEDIUM | 6.5 | 0.2% | Apr 23, 2025 | pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shorten... |
| CVE-2024-10306 | MEDIUM | 5.4 | 0.3% | Apr 23, 2025 | A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <L... |
| CVE-2024-53569 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System... |
| CVE-2024-53568 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4... |
| CVE-2024-12543 | MEDIUM | 5.9 | 0.3% | Apr 21, 2025 | User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows... |
| CVE-2024-42699 | MEDIUM | 6.5 | 0.3% | Apr 21, 2025 | Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to i... |
| CVE-2024-12863 | MEDIUM | 5.6 | 0.3% | Apr 21, 2025 | Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malic... |
| CVE-2024-12862 | MEDIUM | 5.5 | 0.2% | Apr 21, 2025 | Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the... |
| CVE-2024-41446 | MEDIUM | 5.4 | 0.2% | Apr 21, 2025 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scr... |
| CVE-2024-57493 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockop... |
| CVE-2024-41447 | MEDIUM | 5.4 | 0.2% | Apr 18, 2025 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scr... |
| CVE-2024-46089 | MEDIUM | 6.3 | 0.5% | Apr 18, 2025 | 74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin. |
| CVE-2024-49808 | MEDIUM | 6.5 | 0.3% | Apr 18, 2025 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity... |
| CVE-2024-45651 | MEDIUM | 6.5 | 0.3% | Apr 18, 2025 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure w... |
| CVE-2024-13650 | MEDIUM | 6.4 | 0.2% | Apr 18, 2025 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before ... |
| CVE-2024-42177 | MEDIUM | 6.4 | 0.1% | Apr 17, 2025 | HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the... |
| CVE-2024-40124 | MEDIUM | 5.4 | 0.2% | Apr 17, 2025 | Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature. |
| CVE-2024-53304 | MEDIUM | 6.5 | 0.3% | Apr 16, 2025 | An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and ... |
| CVE-2024-40074 | MEDIUM | 4.8 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat... |
| CVE-2024-40070 | MEDIUM | 5.1 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge... |
| CVE-2024-40069 | MEDIUM | 5.4 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat... |
| CVE-2024-40068 | MEDIUM | 5.9 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2024-56736 | MEDIUM | 6.5 | 0.5% | Apr 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating):... |
| CVE-2024-58097 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor d... |
| CVE-2024-58096 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: add srng->lock for ath11k_hal_srng_* ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now