2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-43799MEDIUM4.7Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendS...
CVE-2024-43796MEDIUM4.7Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing ...
CVE-2024-35282MEDIUM4.6A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all ver...
CVE-2024-31490MEDIUM6.5An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4...
CVE-2024-27257MEDIUM4.3IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source...
CVE-2024-25074MEDIUM5.9An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos...
CVE-2024-25073MEDIUM5.9An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos...
CVE-2024-23184MEDIUM5Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header l...
CVE-2024-21753MEDIUM6A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2...
CVE-2024-8369MEDIUM5.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Priv...
CVE-2024-6282MEDIUM5.4The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu...
CVE-2024-8645MEDIUM5.5SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or cr...
CVE-2024-8543MEDIUM5.4The Slider comparison image before and after plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2024-8241MEDIUM5.4The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribut...
CVE-2024-43781MEDIUM6.8A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions ...
CVE-2024-42345MEDIUM4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application ...
CVE-2024-42344MEDIUM5.5A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application ...
CVE-2024-37991MEDIUM6.5A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC R...
CVE-2024-37990MEDIUM6.5A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC R...
CVE-2024-32006MEDIUM6.5A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application ...
CVE-2024-7698MEDIUM5.7A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount C...
CVE-2024-42425MEDIUM5.5Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer ...
CVE-2024-39582MEDIUM4.4Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacke...
CVE-2024-39580MEDIUM6.7Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privilege...
CVE-2024-39574MEDIUM4.4Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now