2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-58344MEDIUM6.4Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to ...
CVE-2024-58343MEDIUM4.3Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie d...
CVE-2024-4867MEDIUM5.4The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or p...
CVE-2024-10242MEDIUM6.1The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. ...
CVE-2024-23104MEDIUM4.3An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 t...
CVE-2024-53828MEDIUM5.3Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large v...
CVE-2024-58342MEDIUM6.1XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does...
CVE-2024-14028MEDIUM6.5Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects...
CVE-2024-46879MEDIUM5.4A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in...
CVE-2024-46878MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and ea...
CVE-2024-51226MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Recor...
CVE-2024-51225MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Man...
CVE-2024-51224MEDIUM4.8Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Recor...
CVE-2024-51223MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag...
CVE-2024-51222MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag...
CVE-2024-13785MEDIUM5.6The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortc...
CVE-2024-31119MEDIUM5.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyl...
CVE-2024-42210MEDIUM5.4A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cros...
CVE-2024-14025MEDIUM6.7An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who ...
CVE-2024-14024MEDIUM6.7An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local n...
CVE-2024-14027MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat...
CVE-2024-35644MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc...
CVE-2024-43035MEDIUM5.8Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V...
CVE-2024-55025MEDIUM6.5Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized a...
CVE-2024-55023MEDIUM5.3Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now