2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45607MEDIUM5.3whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload va...
CVE-2024-8311MEDIUM6.5An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, ...
CVE-2024-4472MEDIUM5.5An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 pr...
CVE-2024-45383MEDIUM5A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus ...
CVE-2024-45303MEDIUM6.1Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rende...
CVE-2024-45182MEDIUM5.5An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds che...
CVE-2024-34336MEDIUM5.3User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists i...
CVE-2024-34335MEDIUM6.1ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability ...
CVE-2024-25270MEDIUM4.3An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulner...
CVE-2024-41629MEDIUM5.5An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive informa...
CVE-2024-8635MEDIUM6.5A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to ...
CVE-2024-6840MEDIUM6.6An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S A...
CVE-2024-6389MEDIUM4.3An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and...
CVE-2024-5435MEDIUM6.5An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all ve...
CVE-2024-4612MEDIUM6.1An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, a...
CVE-2024-6702MEDIUM4.8Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
CVE-2024-6701MEDIUM4.8Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
CVE-2024-6700MEDIUM4.8Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
CVE-2024-6658MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This is...
CVE-2024-42484MEDIUM6.5ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discov...
CVE-2024-42483MEDIUM6.5ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered...
CVE-2024-45856MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a J...
CVE-2024-8750MEDIUM6.1Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve sess...
CVE-2024-8622MEDIUM6.1The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_jav...
CVE-2024-2010MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now