2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38013MEDIUM6.7Microsoft Windows Server Backup Elevation of Privilege Vulnerability
CVE-2024-35270MEDIUM5.3Windows iSCSI Service Denial of Service Vulnerability
CVE-2024-30071MEDIUM4.7Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2024-26279MEDIUM6.1The wrapper extensions do not correctly validate inputs, leading to XSS vectors.
CVE-2024-26278MEDIUM6.1The Custom Fields component not correctly filter inputs, leading to a XSS vector.
CVE-2024-26184MEDIUM6.8Secure Boot Security Feature Bypass Vulnerability
CVE-2024-21731MEDIUM6.1Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
CVE-2024-21730MEDIUM5.4The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
CVE-2024-21729MEDIUM6.1Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
CVE-2024-33509MEDIUM4.8An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all ve...
CVE-2024-27785MEDIUM6.5An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may a...
CVE-2024-27784MEDIUM6.5Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet Forti...
CVE-2024-26015MEDIUM4.7An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, v...
CVE-2024-21759MEDIUM4.3An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7....
CVE-2024-6614MEDIUM4.3The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th...
CVE-2024-6613MEDIUM5.5The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th...
CVE-2024-6612MEDIUM5.3CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This cause...
CVE-2024-6610MEDIUM4.3Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to p...
CVE-2024-6608MEDIUM4.3It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewp...
CVE-2024-6601MEDIUM4.7A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerabilit...
CVE-2024-6600MEDIUM6.3Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allo...
CVE-2024-6598MEDIUM6.5A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It a...
CVE-2024-2177MEDIUM6.8A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 ...
CVE-2024-6391MEDIUM6.4The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bw_button shortcode in all ve...
CVE-2024-39876MEDIUM4A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now