2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-41918MEDIUM6.1'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable t...
CVE-2024-8250MEDIUM5.5NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or...
CVE-2024-45232MEDIUM5.3An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the ...
CVE-2024-45057MEDIUM6.1i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators...
CVE-2024-45048MEDIUM6.5PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypas...
CVE-2024-45046MEDIUM5.4PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpre...
CVE-2024-45054MEDIUM6.7Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resource...
CVE-2024-45043MEDIUM5.3The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream mess...
CVE-2024-43805MEDIUM6.1jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit...
CVE-2024-44915MEDIUM5.5An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a...
CVE-2024-44914MEDIUM5.5An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a...
CVE-2024-44913MEDIUM5.5An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a...
CVE-2024-7744MEDIUM6.5In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path...
CVE-2024-6053MEDIUM4.3Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamV...
CVE-2024-41565MEDIUM5.3JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in In...
CVE-2024-41564MEDIUM5.3EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in I...
CVE-2024-20413MEDIUM6.7A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash ...
CVE-2024-20411MEDIUM6.7A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash ...
CVE-2024-20289MEDIUM4.4A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execu...
CVE-2024-20279MEDIUM4.3A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (...
CVE-2024-42900MEDIUM6.1Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of th...
CVE-2024-42698MEDIUM5.3Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset...
CVE-2024-8195MEDIUM5.3The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2024-7447MEDIUM5.3The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress...
CVE-2024-6450MEDIUM6.1HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unaut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now