2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-36457MEDIUM5.3The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.
CVE-2024-6741MEDIUM5.3Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers c...
CVE-2024-6398MEDIUM5.3An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows inform...
CVE-2024-39767MEDIUM6.5Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually cam...
CVE-2024-32945MEDIUM5.3Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows a...
CVE-2024-6740MEDIUM6.1Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject Jav...
CVE-2024-6540MEDIUM5.3Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS cou...
CVE-2024-6742MEDIUM5.4AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regul...
CVE-2024-6289MEDIUM6.1The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect W...
CVE-2024-6076MEDIUM6.1The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin...
CVE-2024-6074MEDIUM6.1The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin...
CVE-2024-6073MEDIUM6.1The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin...
CVE-2024-6072MEDIUM6.1The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter bef...
CVE-2024-6739MEDIUM6.1The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote att...
CVE-2024-6738MEDIUM5.3The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers t...
CVE-2024-39741MEDIUM5.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the...
CVE-2024-39740MEDIUM5.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could all...
CVE-2024-39735MEDIUM5.4IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2024-39729MEDIUM4.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow an authenticated user to obtain sensitive inform...
CVE-2024-39739MEDIUM4.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to server-side request forgery (SSRF). This ma...
CVE-2024-39737MEDIUM5.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to obtain sensitive informatio...
CVE-2024-39728MEDIUM5.4IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerabi...
CVE-2024-39734MEDIUM4.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or...
CVE-2024-39733MEDIUM5.5IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be rea...
CVE-2024-6730MEDIUM6.3A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This is...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now