2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-42164MEDIUM4.3Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two...
CVE-2024-41890MEDIUM5.3Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: ...
CVE-2024-41888MEDIUM5.3Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: ...
CVE-2024-41482MEDIUM6.1Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.
CVE-2024-41481MEDIUM6.1Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.
CVE-2024-41332MEDIUM6.5Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 al...
CVE-2024-40484MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in "/oahms/search.php" in PHPGurukul Old Age Home Managem...
CVE-2024-40481MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/view-enquiry.php" in PHPGurukul Old Age Home Mana...
CVE-2024-40478MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1...
CVE-2024-40474MEDIUM5.4A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Managem...
CVE-2024-40473MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental M...
CVE-2024-38200MEDIUM6.5Microsoft Office Spoofing Vulnerability
CVE-2024-37283MEDIUM6.5An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the lo...
CVE-2024-36518MEDIUM5.4Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface a...
CVE-2024-32765MEDIUM4.2A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local ...
CVE-2024-22121MEDIUM6.1A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integri...
CVE-2024-22114MEDIUM4.3User with no permission to any of the Hosts can access and view host count & other statistics through System Information...
CVE-2024-21877MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in ...
CVE-2024-0115MEDIUM6.1NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may caus...
CVE-2024-42493MEDIUM5.3Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers an...
CVE-2024-7394MEDIUM4.8Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue a...
CVE-2024-0102MEDIUM5.5NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds...
CVE-2024-7480MEDIUM4.4An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interfa...
CVE-2024-7477MEDIUM6.7A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privil...
CVE-2024-41238MEDIUM5.3A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now