2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38796MEDIUM5.9EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an over...
CVE-2024-9291MEDIUM5.4A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75...
CVE-2024-47186MEDIUM6.1Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2...
CVE-2024-46453MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execut...
CVE-2024-6436MEDIUM6.5An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user...
CVE-2024-9160MEDIUM5.4In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
CVE-2024-46257MEDIUM6.3A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacke...
CVE-2024-38308MEDIUM6.1Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the ...
CVE-2024-37187MEDIUM5.7Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
CVE-2024-34542MEDIUM5.7Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login pr...
CVE-2024-25412MEDIUM6.1A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-25411MEDIUM6.1A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-38809MEDIUM5.3Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of...
CVE-2024-47077MEDIUM6.5authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one appl...
CVE-2024-45745MEDIUM4.3TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute Jav...
CVE-2024-45744MEDIUM4.3TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can r...
CVE-2024-46470MEDIUM6.1Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaS...
CVE-2024-46333MEDIUM4.8An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web sc...
CVE-2024-9283MEDIUM4.8A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown functi...
CVE-2024-47184MEDIUM4.8Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playli...
CVE-2024-45863MEDIUM5.3A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to cr...
CVE-2024-9282MEDIUM4.3A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function...
CVE-2024-9281MEDIUM4.3A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown pr...
CVE-2024-46868MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: Fix deadlock in qcuefi_...
CVE-2024-46867MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: fix deadlock in show_meminfo() Ther...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now