2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-43863MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a deadlock in dma buf fence polling...
CVE-2024-43862MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: wan: fsl_qmc_hdlc: Convert carrier_lock spinlo...
CVE-2024-43861MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: fix memory leak for not ip pack...
CVE-2024-43396MEDIUM5.4Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML in...
CVE-2024-41658MEDIUM6.1Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earl...
CVE-2024-7711MEDIUM4.3An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the ...
CVE-2024-6337MEDIUM6.5An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only ...
CVE-2024-41773MEDIUM6.5IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due t...
CVE-2024-6322MEDIUM5.4Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user...
CVE-2024-43408MEDIUM6.3Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in ...
CVE-2024-42598MEDIUM6.7SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplay...
CVE-2024-40743MEDIUM6.1The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
CVE-2024-27186MEDIUM6.1The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
CVE-2024-27184MEDIUM6.1Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
CVE-2024-43409MEDIUM6.5Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would al...
CVE-2024-43397MEDIUM4.3Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that al...
CVE-2024-43377MEDIUM4.3Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1....
CVE-2024-43376MEDIUM5.3Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is...
CVE-2024-42369MEDIUM5.3matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room o...
CVE-2024-6379MEDIUM6.1A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release...
CVE-2024-6378MEDIUM5.4A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX...
CVE-2024-6377MEDIUM6.1An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPER...
CVE-2024-39094MEDIUM5.4Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix par...
CVE-2024-42560MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Managemen...
CVE-2024-42335MEDIUM5.47Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now