2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-41943MEDIUM4.6I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without ...
CVE-2024-41305MEDIUM4.7A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application t...
CVE-2024-41304MEDIUM5.4An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execut...
CVE-2024-7209MEDIUM6.5A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use net...
CVE-2024-7208MEDIUM6.5A vulnerability in multi-tenant hosting allows an authenticated sender to spoof the identity of a shared, hosted domain,...
CVE-2024-5486MEDIUM4.9A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access ...
CVE-2024-41944MEDIUM6.5Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplay...
CVE-2024-41916MEDIUM4.9A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access ...
CVE-2024-41804MEDIUM6.5Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS...
CVE-2024-41803MEDIUM4.9Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CM...
CVE-2024-41109MEDIUM6.5Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` wi...
CVE-2024-39320MEDIUM6.1Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to...
CVE-2024-37165MEDIUM6.1Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could ...
CVE-2024-7127MEDIUM6.1Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cro...
CVE-2024-41701MEDIUM5.3AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-7225MEDIUM5.4A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This...
CVE-2024-41694MEDIUM5.3Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41693MEDIUM6.1Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-41141MEDIUM6.1Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Ma...
CVE-2024-40895MEDIUM6.4FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a re...
CVE-2024-38430MEDIUM6.1Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-42231MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix calc_available_free_space() for z...
CVE-2024-42230MEDIUM4.4In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Fix scv instruction crash with kex...
CVE-2024-42229MEDIUM4.1In the Linux kernel, the following vulnerability has been resolved: crypto: aead,cipher - zeroize key buffer after use ...
CVE-2024-42227MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix overlapping copy within dml_co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now