2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39308MEDIUM5.4RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerabilit...
CVE-2024-4341MEDIUM6.5Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows ...
CVE-2024-6163MEDIUM5.3Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to by...
CVE-2024-37389MEDIUM5.4Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context con...
CVE-2024-34603MEDIUM5.5Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location dat...
CVE-2024-34602MEDIUM5.5Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local atta...
CVE-2024-37528MEDIUM5.4IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21...
CVE-2024-31897MEDIUM4.3IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21...
CVE-2024-39723MEDIUM4.6IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physic...
CVE-2024-5711MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inj...
CVE-2024-6539MEDIUM4.8A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unkno...
CVE-2024-6229MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the 'Upload Knowledge' feature of stangirard/quivr, affectin...
CVE-2024-40605MEDIUM4.8An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar t...
CVE-2024-40604MEDIUM4.8An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sideba...
CVE-2024-40603MEDIUM4.3An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF t...
CVE-2024-40602MEDIUM4.8An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-le...
CVE-2024-40601MEDIUM6.5An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.
CVE-2024-40600MEDIUM4.8An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar to...
CVE-2024-40599MEDIUM4.8An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-...
CVE-2024-40598MEDIUM4.3An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed informati...
CVE-2024-40596MEDIUM4.3An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can exp...
CVE-2024-6095MEDIUM5.8A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (...
CVE-2024-37554MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Ultra...
CVE-2024-37553MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Axelerant T...
CVE-2024-37547MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now