2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45741MEDIUM5.4In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.2...
CVE-2024-45740MEDIUM5.4In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged ...
CVE-2024-45739MEDIUM4.9In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for lo...
CVE-2024-45738MEDIUM4.9In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters ...
CVE-2024-45736MEDIUM6.5In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2...
CVE-2024-45735MEDIUM4.3In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform version...
CVE-2024-45734MEDIUM4.3In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" S...
CVE-2024-45732MEDIUM6.5In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2....
CVE-2024-8184MEDIUM6.5There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized u...
CVE-2024-6763MEDIUM5.3Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class,...
CVE-2024-6762MEDIUM6.5Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s...
CVE-2024-41997MEDIUM6.6An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulne...
CVE-2024-9936MEDIUM6.5When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially lea...
CVE-2024-8602MEDIUM6.3When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentB...
CVE-2024-48120MEDIUM5.4X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma...
CVE-2024-48119MEDIUM5.4Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary H...
CVE-2024-46911MEDIUM4.7Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websi...
CVE-2024-38862MEDIUM4.4Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and ...
CVE-2024-9923MEDIUM4.9The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with ...
CVE-2024-49214MEDIUM5.3QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a...
CVE-2024-9917MEDIUM4.9A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the f...
CVE-2024-9907MEDIUM6.3A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function send...
CVE-2024-9906MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is a...
CVE-2024-8902MEDIUM4.3The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2024-9696MEDIUM5.4The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' sh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now