2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-37879MEDIUM4.8Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrato...
CVE-2024-9036MEDIUM6.3A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some u...
CVE-2024-9033MEDIUM5.4A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. ...
CVE-2024-9031MEDIUM5.4A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affe...
CVE-2024-9030MEDIUM5.4A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown cod...
CVE-2024-47060MEDIUM6.5Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associate...
CVE-2024-46999MEDIUM6.5Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correc...
CVE-2024-45808MEDIUM6.5Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that al...
CVE-2024-45806MEDIUM6.5Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external cl...
CVE-2024-9007MEDIUM5.4A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of...
CVE-2024-45614MEDIUM5.4Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermedi...
CVE-2024-9003MEDIUM5.3A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects th...
CVE-2024-38221MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-25673MEDIUM6.1Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
CVE-2024-47162MEDIUM5.3In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
CVE-2024-47160MEDIUM5.3In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
CVE-2024-47159MEDIUM4.3In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a pro...
CVE-2024-8653MEDIUM6.1A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific...
CVE-2024-8652MEDIUM6.1A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific...
CVE-2024-8651MEDIUM5.3A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whet...
CVE-2024-8883MEDIUM6.1A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if...
CVE-2024-7736MEDIUM5.4A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX...
CVE-2024-8354MEDIUM5.5A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to ...
CVE-2024-45770MEDIUM4.4A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a ...
CVE-2024-45769MEDIUM5.5A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now