2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45180MEDIUM5.4SquaredUp DS for SCOM 6.2.1.11104 allows XSS.
CVE-2024-41434MEDIUM4.3PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows atta...
CVE-2024-43803MEDIUM4.9The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (...
CVE-2024-43413MEDIUM4.8Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr...
CVE-2024-42904MEDIUM6.1A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2024-42903MEDIUM6.5A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows atta...
CVE-2024-42901MEDIUM4.8A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted ...
CVE-2024-43412MEDIUM5.4Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr...
CVE-2024-7654MEDIUM6.1An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-dis...
CVE-2024-7346MEDIUM4.8Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perfo...
CVE-2024-34463MEDIUM5.1BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The p...
CVE-2024-8388MEDIUM5.3Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing th...
CVE-2024-8386MEDIUM6.1If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of anot...
CVE-2024-44920MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to e...
CVE-2024-37136MEDIUM4.9Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Ac...
CVE-2024-42061MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmwar...
CVE-2024-6343MEDIUM4.9A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG F...
CVE-2024-45621MEDIUM5.4The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related t...
CVE-2024-6920MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunicat...
CVE-2024-45313MEDIUM5.4Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 20...
CVE-2024-45312MEDIUM5.3Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or...
CVE-2024-45308MEDIUM6.5HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or Ma...
CVE-2024-45306MEDIUM5.5Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and rem...
CVE-2024-44947MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before se...
CVE-2024-43801MEDIUM5.4Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now