2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-36527MEDIUM6.5puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter usin...
CVE-2024-36578MEDIUM5.9akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.
CVE-2024-36574MEDIUM6.3A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflat...
CVE-2024-38470MEDIUM6.1zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par...
CVE-2024-38469MEDIUM6.3zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par...
CVE-2024-37625MEDIUM6.1zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par...
CVE-2024-37624MEDIUM6.1Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inpu...
CVE-2024-37623MEDIUM6.1Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_k...
CVE-2024-37622MEDIUM6.1Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter...
CVE-2024-37620MEDIUM6.1PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view...
CVE-2024-37619MEDIUM6.1StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id par...
CVE-2024-37159MEDIUM6.5Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a val...
CVE-2024-6055MEDIUM4.7Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32....
CVE-2024-5741MEDIUM5.4Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)
CVE-2024-36289MEDIUM5.3Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for An...
CVE-2024-36279MEDIUM5.3Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom -...
CVE-2024-36277MEDIUM5.3Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3...
CVE-2024-4305MEDIUM6.8The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape som...
CVE-2024-3236MEDIUM5.4The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which cou...
CVE-2024-6044MEDIUM6.5Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same loc...
CVE-2024-38465MEDIUM5.3Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of i...
CVE-2024-38460MEDIUM6.5In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially...
CVE-2024-38454MEDIUM6.1ExpressionEngine before 7.4.11 allows XSS.
CVE-2024-38443MEDIUM6.2C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, whi...
CVE-2024-36397MEDIUM6.1Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site S...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now