2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9007MEDIUM5.4A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of...
CVE-2024-45614MEDIUM5.4Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermedi...
CVE-2024-9003MEDIUM5.3A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects th...
CVE-2024-38221MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-25673MEDIUM6.1Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
CVE-2024-47162MEDIUM5.3In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
CVE-2024-47160MEDIUM5.3In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
CVE-2024-47159MEDIUM4.3In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a pro...
CVE-2024-8653MEDIUM6.1A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific...
CVE-2024-8652MEDIUM6.1A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific...
CVE-2024-8651MEDIUM5.3A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whet...
CVE-2024-8883MEDIUM6.1A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if...
CVE-2024-7736MEDIUM5.4A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX...
CVE-2024-8354MEDIUM5.5A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to ...
CVE-2024-45770MEDIUM4.4A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a ...
CVE-2024-45769MEDIUM5.5A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to...
CVE-2024-47089MEDIUM6.5This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API ...
CVE-2024-47087MEDIUM6.5This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID ...
CVE-2024-47086MEDIUM6.5This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism ...
CVE-2024-47085MEDIUM6.5This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClic...
CVE-2024-8850MEDIUM6.1The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' ...
CVE-2024-8364MEDIUM5.4The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-pre...
CVE-2024-47059MEDIUM4.3When logging in with the correct username and incorrect weak password, the user receives the notification, that their pa...
CVE-2024-47058MEDIUM4.8With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use...
CVE-2024-47050MEDIUM6.1Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variabl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now