2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8800MEDIUM6.1The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and m...
CVE-2024-8254MEDIUM6.3The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-9333MEDIUM5.3Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited am...
CVE-2024-9174MEDIUM5.4Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
CVE-2024-21530MEDIUM4.5Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, ...
CVE-2024-9407MEDIUM4.7A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not pro...
CVE-2024-47609MEDIUM6.9Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server ther...
CVE-2024-47528MEDIUM4.8LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be ach...
CVE-2024-47527MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-47525MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-47524MEDIUM4.8LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Gro...
CVE-2024-47523MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-46082MEDIUM5.4Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parame...
CVE-2024-9411MEDIUM5.3A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admi...
CVE-2024-9355MEDIUM6.5A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized b...
CVE-2024-46083MEDIUM5.4Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p...
CVE-2024-46081MEDIUM5.4Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p...
CVE-2024-46079MEDIUM6.1Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
CVE-2024-31835MEDIUM4.8Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code vi...
CVE-2024-9398MEDIUM5.3By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if...
CVE-2024-9397MEDIUM6.1A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permiss...
CVE-2024-9395MEDIUM5.3A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in th...
CVE-2024-9391MEDIUM6.5A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full scr...
CVE-2024-47604MEDIUM6.1NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handli...
CVE-2024-47071MEDIUM6.8OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authent...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now