2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35582MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...
CVE-2024-35581MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...
CVE-2024-28061MEDIUM6.3An issue was discovered in Apiris Kafeo 6.4.4. It permits a bypass, of the protection in place, to access to the data st...
CVE-2024-5434MEDIUM6.9The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwo...
CVE-2024-5433MEDIUM5.3The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given exp...
CVE-2024-36107MEDIUM5.3MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` an...
CVE-2024-35401MEDIUM5.9TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName para...
CVE-2024-35342MEDIUM4.6Certain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volu...
CVE-2024-34852MEDIUM6.3F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point ...
CVE-2024-30164MEDIUM6.7Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands wit...
CVE-2024-36472MEDIUM6.5In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network ...
CVE-2024-35621MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute ar...
CVE-2024-33849MEDIUM6.5ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.
CVE-2024-33807MEDIUM5.4A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management Syst...
CVE-2024-33804MEDIUM6.3A SQL injection vulnerability in /model/get_subject.php in campcodes Complete Web-Based School Management System 1.0 all...
CVE-2024-33803MEDIUM5.4A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows...
CVE-2024-33802MEDIUM6.5A SQL injection vulnerability in /model/get_student_subject.php in campcodes Complete Web-Based School Management System...
CVE-2024-35400MEDIUM5.3TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function...
CVE-2024-2451MEDIUM6.4Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows ...
CVE-2024-5428MEDIUM4.3A vulnerability classified as problematic was found in SourceCodester Simple Online Bidding System 1.0. Affected by this...
CVE-2024-24584MEDIUM4.3Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .ms...
CVE-2024-24583MEDIUM4.3Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .ms...
CVE-2024-5413MEDIUM6.1A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS...
CVE-2024-2199MEDIUM5.7A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to ca...
CVE-2024-28793MEDIUM5.4IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configur...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now