2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41503MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) insid...
CVE-2024-41502MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (o...
CVE-2024-37396MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users t...
CVE-2024-37395MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated us...
CVE-2024-37394MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users ...
CVE-2024-57190CRITICAL9.8Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP...
CVE-2024-57189MEDIUM5.4In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerabili...
CVE-2024-57186MEDIUM5.4In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerabili...
CVE-2024-54019MEDIUM6.5A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 thr...
CVE-2024-50568MEDIUM5.9A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 thro...
CVE-2024-50562MEDIUM4.8An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve...
CVE-2024-45329MEDIUM4.3A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,...
CVE-2024-43706HIGH8.8Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
CVE-2024-32119MEDIUM4.8An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an u...
CVE-2024-41797MEDIUM5.3A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK53...
CVE-2024-40625MEDIUM4.9GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspace...
CVE-2024-38524HIGH7.5GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispa...
CVE-2024-34711HIGH8.2GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne...
CVE-2024-29198HIGH8.2GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It poss...
CVE-2024-13090HIGH7.3A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configure...
CVE-2024-13089HIGH7.5An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut...
CVE-2024-55595Rejected reason: Not used
CVE-2024-47081MEDIUM5.3Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to...
CVE-2024-46452MEDIUM6.1A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b a...
CVE-2024-55585CRITICAL9In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, re...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now