2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-46372MEDIUM6.1DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement manageme...
CVE-2024-43025MEDIUM6.1An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and...
CVE-2024-43024MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to...
CVE-2024-46989MEDIUM5.3spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom...
CVE-2024-46979MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t...
CVE-2024-46978MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible f...
CVE-2024-46959MEDIUM6.5runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows ac...
CVE-2024-46990MEDIUM5Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to loca...
CVE-2024-45813MEDIUM5.3find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route ...
CVE-2024-45298MEDIUM4.3Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the pass...
CVE-2024-6877MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Softwa...
CVE-2024-5959MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Softwa...
CVE-2024-8891MEDIUM5.3An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users a...
CVE-2024-39081MEDIUM4.2An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communicat...
CVE-2024-5682MEDIUM6.9Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library ...
CVE-2024-43188MEDIUM4.9IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthor...
CVE-2024-46801MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: libfs: fix get_stashed_dentry() get_stashed_dentry...
CVE-2024-46799MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: Fix NULL dereference ...
CVE-2024-46797MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: powerpc/qspinlock: Fix deadlock in MCS queue If an...
CVE-2024-46795MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset the binding mark of a reused connectio...
CVE-2024-46793MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: Boards: Fix NULL pointer deref in BYT/...
CVE-2024-46791MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: mcp251x: fix deadlock if an interrupt occurs d...
CVE-2024-46790MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: codetag: debug: mark codetags for poisoned page as ...
CVE-2024-46789MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/slub: add check for s->flags in the alloc_taggin...
CVE-2024-46788MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Use a cpumask to know what threads...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now