2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10445MEDIUM5.3Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-653...
CVE-2024-57151MEDIUM6.8SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via...
CVE-2024-57170MEDIUM6.5SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" paramete...
CVE-2024-49822MEDIUM4.1IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authentica...
CVE-2024-44314MEDIUM6.5TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthor...
CVE-2024-41975MEDIUM5.3An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs p...
CVE-2024-54565MEDIUM6.2The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access se...
CVE-2024-54559MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access se...
CVE-2024-8510MEDIUM5.3N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Custom...
CVE-2024-44866MEDIUM6.8A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary c...
CVE-2024-48828MEDIUM5.5Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Mana...
CVE-2024-48017MEDIUM6.5Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization...
CVE-2024-48015MEDIUM6.7Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization...
CVE-2024-9055MEDIUM4.2The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allo...
CVE-2024-54027MEDIUM4.4A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and...
CVE-2024-13602MEDIUM4.8The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-13126MEDIUM4.6The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htac...
CVE-2024-58103MEDIUM5.8Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReade...
CVE-2024-13497MEDIUM6.1The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t...
CVE-2024-12336MEDIUM6.5The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of ...
CVE-2024-29409MEDIUM5.5File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Typ...
CVE-2024-12020MEDIUM6.1There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica...
CVE-2024-40585MEDIUM6.5An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2...
CVE-2024-47573MEDIUM6.5An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2...
CVE-2024-45638MEDIUM4.4IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now