2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47178MEDIUM5.3basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe...
CVE-2024-47067MEDIUM6.1AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerabil...
CVE-2024-46869MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver...
CVE-2024-46475MEDIUM4.8A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows at...
CVE-2024-47172MEDIUM5.4Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke...
CVE-2024-47064MEDIUM6.1Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an atta...
CVE-2024-47063MEDIUM6.1Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malic...
CVE-2024-45792MEDIUM6.5Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered...
CVE-2024-6051MEDIUM4.3Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection ...
CVE-2024-47641MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel C...
CVE-2024-45920MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts ...
CVE-2024-9329MEDIUM6.1In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the ...
CVE-2024-8459MEDIUM4.9Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, ...
CVE-2024-8457MEDIUM4.8Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters,...
CVE-2024-8455MEDIUM5.9The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authe...
CVE-2024-8453MEDIUM4.9Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salte...
CVE-2024-45200MEDIUM6.3In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to e...
CVE-2024-41999MEDIUM6.8Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability...
CVE-2024-8449MEDIUM6.8Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allo...
CVE-2024-8536MEDIUM5.4The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outp...
CVE-2024-8283MEDIUM4.8The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow...
CVE-2024-8239MEDIUM5.4The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like...
CVE-2024-3635MEDIUM4.8The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow h...
CVE-2024-9323MEDIUM5.4A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affect...
CVE-2024-9321MEDIUM5.3A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now