2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-14028MEDIUM6.5Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects...
CVE-2024-46879MEDIUM5.4A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in...
CVE-2024-46878MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and ea...
CVE-2024-51226MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Recor...
CVE-2024-51225MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Man...
CVE-2024-51224MEDIUM4.8Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Recor...
CVE-2024-51223MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag...
CVE-2024-51222MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag...
CVE-2024-13785MEDIUM5.6The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortc...
CVE-2024-31119MEDIUM5.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyl...
CVE-2024-42210MEDIUM5.4A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cros...
CVE-2024-14025MEDIUM6.7An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who ...
CVE-2024-14024MEDIUM6.7An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local n...
CVE-2024-14027MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat...
CVE-2024-35644MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc...
CVE-2024-43035MEDIUM5.8Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V...
CVE-2024-55025MEDIUM6.5Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized a...
CVE-2024-55023MEDIUM5.3Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow...
CVE-2024-43766MEDIUM6.5In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th...
CVE-2024-50337MEDIUM5.3Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to...
CVE-2024-10938MEDIUM6.5The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives ...
CVE-2024-56208MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in desertthemes NewsM...
CVE-2024-54222MEDIUM4.3Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Accelerator seraphinite-accelerator allows Retr...
CVE-2024-52387MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste...
CVE-2024-51915MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now