2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-44540MEDIUM6.6Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command s...
CVE-2024-43201MEDIUM5.9The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker...
CVE-2024-39843MEDIUM6.7A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm...
CVE-2024-39342MEDIUM6.6Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier use...
CVE-2024-39341MEDIUM5.9Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and...
CVE-2024-9014MEDIUM6.5pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows ...
CVE-2024-40441MEDIUM6.6An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi...
CVE-2024-47069MEDIUM6.1Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy set...
CVE-2024-47068MEDIUM6.1Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobber...
CVE-2024-23972MEDIUM6.8Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-23933MEDIUM6.8Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows p...
CVE-2024-23922MEDIUM6.8Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows p...
CVE-2024-46241MEDIUM5.9PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in...
CVE-2024-46544MEDIUM5.9Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared mem...
CVE-2024-8903MEDIUM4.7Local active protection service settings manipulation due to unnecessary privileges assignment. The following products a...
CVE-2024-8758MEDIUM4.8The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which...
CVE-2024-7846MEDIUM5.4YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied bloc...
CVE-2024-47227MEDIUM6.1iRedAdmin before 2.6 allows XSS, e.g., via order_name.
CVE-2024-9092MEDIUM6.1A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as proble...
CVE-2024-44048MEDIUM6.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-43996MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit ...
CVE-2024-9089MEDIUM5.4A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue ...
CVE-2024-40703MEDIUM5.5IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Re...
CVE-2024-9084MEDIUM5.4A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u...
CVE-2024-9083MEDIUM4.8A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now