2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-41843MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-41842MEDIUM4.8Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-41841MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-43032MEDIUM4.3autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.
CVE-2024-43031MEDIUM4.3autMan v2.9.6 was discovered to contain an access control issue.
CVE-2024-42364MEDIUM6.5Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1...
CVE-2024-8113MEDIUM5.4Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tag...
CVE-2024-8112MEDIUM6.1A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown pro...
CVE-2024-42766MEDIUM5.4Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.
CVE-2024-41150MEDIUM6.1An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDe...
CVE-2024-38869MEDIUM5.4Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configu...
CVE-2024-5502MEDIUM5.4The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Imag...
CVE-2024-38807MEDIUM6.3Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature v...
CVE-2024-43105MEDIUM4.3Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a...
CVE-2024-6715MEDIUM6.1The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerabil...
CVE-2024-3282MEDIUM4.8The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could al...
CVE-2024-38208MEDIUM6.1Microsoft Edge for Android Spoofing Vulnerability
CVE-2024-8084MEDIUM4.8A vulnerability, which was classified as problematic, was found in SourceCodester Online Computer and Laptop Store 1.0. ...
CVE-2024-43790MEDIUM5.5Vim is an open source command line text editor. When performing a search and displaying the search-count message is disa...
CVE-2024-42763MEDIUM5.4A Reflected Cross Site Scripting (XSS) vulnerability was found in the "/schedule.php" page of the Kashipara Bus Ticket R...
CVE-2024-42762MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System...
CVE-2024-42761MEDIUM6.1A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin_schedule.php" in Kashipara Bus Ticket Reservation...
CVE-2024-7634MEDIUM4.9NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwri...
CVE-2024-42768MEDIUM6.8A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_...
CVE-2024-8041MEDIUM6.5A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now