2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35627MEDIUM6.1tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data...
CVE-2024-31904MEDIUM6.5IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an au...
CVE-2024-31893MEDIUM4.3IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar inf...
CVE-2024-25737MEDIUM5.4A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open ...
CVE-2024-31617MEDIUM5.3OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
CVE-2024-29421MEDIUM6.2xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to...
CVE-2024-5166MEDIUM6.5An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users...
CVE-2024-20363MEDIUM5.8Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that ...
CVE-2024-20361MEDIUM5.8A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) ...
CVE-2024-20355MEDIUM5A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive ...
CVE-2024-20293MEDIUM5.8A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software an...
CVE-2024-20261MEDIUM5.8A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Def...
CVE-2024-35362MEDIUM5.4Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.
CVE-2024-29392MEDIUM5.4Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.
CVE-2024-3926MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-35561MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add...
CVE-2024-35560MEDIUM4.3idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del...
CVE-2024-35557MEDIUM5.5idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi...
CVE-2024-35555MEDIUM6.3idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mud...
CVE-2024-35554MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mud...
CVE-2024-35551MEDIUM4.3idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mud...
CVE-2024-35550MEDIUM6.3idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mud...
CVE-2024-35475MEDIUM6.4A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12...
CVE-2024-4261MEDIUM5.4The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-36010MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: igb: Fix string truncation warnings in igb_set_fw_v...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now