2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45597MEDIUM5.3Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to ht...
CVE-2024-8441MEDIUM6.7An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local auth...
CVE-2024-8320MEDIUM5.3Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote ...
CVE-2024-8655MEDIUM6.9A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unk...
CVE-2024-45596MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access cred...
CVE-2024-34831MEDIUM6.1cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the im...
CVE-2024-44872MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the...
CVE-2024-43487MEDIUM6.5Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2024-43482MEDIUM6.5Microsoft Outlook for iOS Information Disclosure Vulnerability
CVE-2024-43476MEDIUM5.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-38256MEDIUM5.5Windows Kernel-Mode Driver Information Disclosure Vulnerability
CVE-2024-38254MEDIUM6.2Windows Authentication Information Disclosure Vulnerability
CVE-2024-38235MEDIUM6.5Windows Hyper-V Denial of Service Vulnerability
CVE-2024-38234MEDIUM6.5Windows Networking Denial of Service Vulnerability
CVE-2024-38217MEDIUM5.4Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2024-37342MEDIUM4.3Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
CVE-2024-37337MEDIUM4.3Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
CVE-2024-6876MEDIUM4.4Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited interna...
CVE-2024-45592MEDIUM6.1auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Pri...
CVE-2024-45591MEDIUM5.3XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker k...
CVE-2024-45407MEDIUM5.3Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing proce...
CVE-2024-44815MEDIUM4.6Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credent...
CVE-2024-44676MEDIUM4.8eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code v...
CVE-2024-45393MEDIUM6.4Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke...
CVE-2024-43800MEDIUM4.7serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() ma...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now