2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7562HIGH7.3A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple In...
CVE-2024-44906MEDIUM6.5uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/...
CVE-2024-44905MEDIUM6.5go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
CVE-2024-56158CRITICAL9.8XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGE...
CVE-2024-9512MEDIUM5.9An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prio...
CVE-2024-35295MEDIUM6.1A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manu...
CVE-2024-1244CRITICAL9.5Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control ...
CVE-2024-1243CRITICAL9.5Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the...
CVE-2024-9062HIGH7.8The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its...
CVE-2024-8270MEDIUM5.5The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Contr...
CVE-2024-7457HIGH7.8The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization mod...
CVE-2024-41505MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section...
CVE-2024-41504MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportuni...
CVE-2024-41503MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) insid...
CVE-2024-41502MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (o...
CVE-2024-37396MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users t...
CVE-2024-37395MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated us...
CVE-2024-37394MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users ...
CVE-2024-57190CRITICAL9.8Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP...
CVE-2024-57189MEDIUM5.4In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerabili...
CVE-2024-57186MEDIUM5.4In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerabili...
CVE-2024-54019MEDIUM6.5A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 thr...
CVE-2024-50568MEDIUM5.9A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 thro...
CVE-2024-50562MEDIUM4.8An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve...
CVE-2024-45329MEDIUM4.3A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now