2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-37034MEDIUM5.9An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are...
CVE-2024-42007MEDIUM5.8SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.
CVE-2024-41375MEDIUM6.1ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
CVE-2024-41374MEDIUM6.1ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
CVE-2024-41373MEDIUM6.3ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
CVE-2024-27357MEDIUM5.8An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through...
CVE-2024-41356MEDIUM4.7phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.
CVE-2024-41355MEDIUM6.5phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
CVE-2024-41805MEDIUM6.1Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior t...
CVE-2024-7128MEDIUM5.3A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWit...
CVE-2024-6922MEDIUM6.9Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attac...
CVE-2024-41691MEDIUM4.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within th...
CVE-2024-41690MEDIUM4.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credenti...
CVE-2024-41689MEDIUM4.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials withi...
CVE-2024-41688MEDIUM4.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passw...
CVE-2024-41684MEDIUM5.3This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies assoc...
CVE-2024-25090MEDIUM5.4Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name...
CVE-2024-6490MEDIUM6.5During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an un...
CVE-2024-40897MEDIUM6.7Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricke...
CVE-2024-3938MEDIUM6.1The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patc...
CVE-2024-38103MEDIUM5.9Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-41809MEDIUM6.1OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve...
CVE-2024-6558MEDIUM6.1HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanita...
CVE-2024-41808MEDIUM5.4The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uplo...
CVE-2024-40324MEDIUM5.4A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) charac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now