2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-41587MEDIUM5.4Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor31...
CVE-2024-41585MEDIUM6.8DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker ...
CVE-2024-41584MEDIUM4.7DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing vali...
CVE-2024-41583MEDIUM4.7DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due...
CVE-2024-47762MEDIUM5.8Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment v...
CVE-2024-34535MEDIUM5.9In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
CVE-2024-8508MEDIUM5.3NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRs...
CVE-2024-45872MEDIUM6.3Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient...
CVE-2024-45871MEDIUM6.3Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).
CVE-2024-45870MEDIUM6.5Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.
CVE-2024-9100MEDIUM6.5Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnera...
CVE-2024-47618MEDIUM5.4Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the...
CVE-2024-47617MEDIUM6.1Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code ...
CVE-2024-47554MEDIUM4.3Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader c...
CVE-2024-42504MEDIUM4.3A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery...
CVE-2024-8159MEDIUM6.4Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of t...
CVE-2024-47616MEDIUM6.8Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all ...
CVE-2024-47529MEDIUM6.5OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2024-46977MEDIUM6.5OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2024-45965MEDIUM5.4Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54,...
CVE-2024-45964MEDIUM4.8Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.
CVE-2024-45962MEDIUM4.7October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the targe...
CVE-2024-45960MEDIUM4.8Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system....
CVE-2024-43795MEDIUM6.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2024-9440MEDIUM6.1Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:crea...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now