2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39310MEDIUM5.4The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` paramet...
CVE-2024-37764MEDIUM5.4MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
CVE-2024-37763MEDIUM5.4MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid s...
CVE-2024-23737MEDIUM5.4Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows a...
CVE-2024-32228MEDIUM6.6FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.
CVE-2024-39303MEDIUM5.4Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when resto...
CVE-2024-37146MEDIUM6.1Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ...
CVE-2024-37145MEDIUM6.1Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ...
CVE-2024-36423MEDIUM6.1Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ...
CVE-2024-36387MEDIUM5.4Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a cr...
CVE-2024-39879MEDIUM5.3In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
CVE-2024-39878MEDIUM5.3In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
CVE-2024-36996MEDIUM5.3In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an a...
CVE-2024-36994MEDIUM5.4In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-36993MEDIUM5.4In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-36992MEDIUM5.4In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-36990MEDIUM6.5In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an a...
CVE-2024-36989MEDIUM4.3In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a lo...
CVE-2024-36987MEDIUM6.5In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an a...
CVE-2024-36986MEDIUM5.7In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-20399MEDIUM6.7A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator cred...
CVE-2024-36422MEDIUM6.1Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ...
CVE-2024-6375MEDIUM6.5A command for refining a collection shard key is missing an authorization check. This may cause the command to run direc...
CVE-2024-34696MEDIUM4.9GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and p...
CVE-2024-21462MEDIUM5.5Transient DOS while loading the TA ELF file.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now