2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4907MEDIUM6.5A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. ...
CVE-2024-3182MEDIUM6.5Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versi...
CVE-2024-20394MEDIUM5.5A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a ...
CVE-2024-20392MEDIUM6.1A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an ...
CVE-2024-20391MEDIUM6.8A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacke...
CVE-2024-20369MEDIUM6.1A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow...
CVE-2024-20258MEDIUM6.1A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager a...
CVE-2024-20257MEDIUM4.8A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could all...
CVE-2024-20256MEDIUM4.8A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager a...
CVE-2024-4837MEDIUM5.3In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gai...
CVE-2024-4357MEDIUM6.5An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earli...
CVE-2024-3892MEDIUM6.7A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024....
CVE-2024-28087MEDIUM6.5In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions ...
CVE-2024-27593MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allo...
CVE-2024-4903MEDIUM6.3A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code o...
CVE-2024-3318MEDIUM4.2A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authent...
CVE-2024-3317MEDIUM6.5An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authen...
CVE-2024-35179MEDIUM6.8Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user...
CVE-2024-31216MEDIUM5.1The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, ...
CVE-2024-34954MEDIUM6.1Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.
CVE-2024-2248MEDIUM6.4A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allo...
CVE-2024-4702MEDIUM5.4The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in al...
CVE-2024-34101MEDIUM5.5Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerabili...
CVE-2024-30312MEDIUM5.5Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerabili...
CVE-2024-30311MEDIUM5.5Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerabili...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now