2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-43797MEDIUM4.3audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or ac...
CVE-2024-43792MEDIUM6.1Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 o...
CVE-2024-28100MEDIUM5.4eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular use...
CVE-2024-8004MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER...
CVE-2024-7939MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an ...
CVE-2024-7938MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x thr...
CVE-2024-7932MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allow...
CVE-2024-38858MEDIUM6.1Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts...
CVE-2024-33043MEDIUM5.5Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-33016MEDIUM6.8memory corruption when an invalid firehose patch command is invoked.
CVE-2024-7692MEDIUM6.1The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-7691MEDIUM6.1The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthe...
CVE-2024-7690MEDIUM4.3The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could al...
CVE-2024-7354MEDIUM6.1The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leadin...
CVE-2024-8365MEDIUM6.5Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers ...
CVE-2024-45528MEDIUM5.4CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.
CVE-2024-45527MEDIUM6.1REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSR...
CVE-2024-39612MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-38382MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-28044MEDIUM5.5in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.
CVE-2024-20088MEDIUM4.4In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio...
CVE-2024-20087MEDIUM6.7In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2024-20086MEDIUM6.7In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2024-20085MEDIUM4.4In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis...
CVE-2024-20084MEDIUM4.4In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now