2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9077MEDIUM5.4A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. A...
CVE-2024-47226MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of t...
CVE-2024-9075MEDIUM5.4A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnera...
CVE-2024-9048MEDIUM6.1A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerab...
CVE-2024-8680MEDIUM5.5The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ...
CVE-2024-6787MEDIUM5.9This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it ...
CVE-2024-6786MEDIUM6.5The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling the...
CVE-2024-46647MEDIUM6.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
CVE-2024-46646MEDIUM6.5eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
CVE-2024-46644MEDIUM6.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
CVE-2024-45793MEDIUM4.8Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The foll...
CVE-2024-46654MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows at...
CVE-2024-45229MEDIUM6.6The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen,...
CVE-2024-42346MEDIUM5.4Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, ...
CVE-2024-42697MEDIUM6.1Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to...
CVE-2024-9040MEDIUM5.5A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This ...
CVE-2024-37879MEDIUM4.8Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrato...
CVE-2024-9036MEDIUM6.3A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some u...
CVE-2024-9033MEDIUM5.4A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. ...
CVE-2024-9031MEDIUM5.4A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affe...
CVE-2024-9030MEDIUM5.4A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown cod...
CVE-2024-47060MEDIUM6.5Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associate...
CVE-2024-46999MEDIUM6.5Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correc...
CVE-2024-45808MEDIUM6.5Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that al...
CVE-2024-45806MEDIUM6.5Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external cl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now