2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-42397MEDIUM5.3Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed ...
CVE-2024-42396MEDIUM5.3Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed ...
CVE-2024-42347MEDIUM6.5matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver c...
CVE-2024-41677MEDIUM6.1Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions u...
CVE-2024-42358MEDIUM5.5PDFio is a simple C library for reading and writing PDF files. There is a denial of service (DOS) vulnerability in the T...
CVE-2024-39229MEDIUM5.3An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT...
CVE-2024-7564MEDIUM6.5Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remo...
CVE-2024-7005MEDIUM4.3Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote att...
CVE-2024-7004MEDIUM4.3Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote att...
CVE-2024-7003MEDIUM4.3Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a ...
CVE-2024-7001MEDIUM4.3Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a u...
CVE-2024-6999MEDIUM4.3Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a ...
CVE-2024-6995MEDIUM4.7Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker ...
CVE-2024-43113MEDIUM6.1The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects F...
CVE-2024-43112MEDIUM6.1Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects F...
CVE-2024-43111MEDIUM6.1Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vuln...
CVE-2024-41333MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to ex...
CVE-2024-39751MEDIUM4.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2024-23464MEDIUM4.9In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Z...
CVE-2024-36424MEDIUM5.5K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of ...
CVE-2024-41911MEDIUM5.4A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not...
CVE-2024-41910MEDIUM6.1A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware con...
CVE-2024-40101MEDIUM6.1A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unaut...
CVE-2024-7551MEDIUM4.9A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown func...
CVE-2024-7531MEDIUM6.5Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now