2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8510MEDIUM5.3N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Custom...
CVE-2024-44866MEDIUM6.8A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary c...
CVE-2024-48828MEDIUM5.5Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Mana...
CVE-2024-48017MEDIUM6.5Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization...
CVE-2024-48015MEDIUM6.7Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization...
CVE-2024-9055MEDIUM4.2The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allo...
CVE-2024-54027MEDIUM4.4A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and...
CVE-2024-13602MEDIUM4.8The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-13126MEDIUM4.6The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htac...
CVE-2024-58103MEDIUM5.8Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReade...
CVE-2024-13497MEDIUM6.1The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t...
CVE-2024-12336MEDIUM6.5The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of ...
CVE-2024-29409MEDIUM5.5File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Typ...
CVE-2024-12020MEDIUM6.1There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica...
CVE-2024-40585MEDIUM6.5An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2...
CVE-2024-47573MEDIUM6.5An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2...
CVE-2024-45638MEDIUM4.4IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.
CVE-2024-40590MEDIUM4.8An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio...
CVE-2024-13772MEDIUM5.9The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass...
CVE-2024-13771MEDIUM5.9The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass...
CVE-2024-26006MEDIUM6.1An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below...
CVE-2024-13407MEDIUM6.5The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via...
CVE-2024-55060MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to exe...
CVE-2024-30143MEDIUM4.3HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing...
CVE-2024-9042MEDIUM5.9This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now