2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4513MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management S...
CVE-2024-4512MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability a...
CVE-2024-4511MEDIUM6.3A vulnerability classified as critical has been found in Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4. Th...
CVE-2024-34529MEDIUM4.8Nebari through 2024.4.1 prints the temporary Keycloak root password.
CVE-2024-34525MEDIUM5.3FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.
CVE-2024-34519MEDIUM6.8Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a use...
CVE-2024-34509MEDIUM5.3dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.
CVE-2024-34508MEDIUM4.3dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.
CVE-2024-34500MEDIUM6.1An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x b...
CVE-2024-34490MEDIUM5.1In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the cont...
CVE-2024-34484MEDIUM5.3OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.l...
CVE-2024-34476MEDIUM5.3Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_...
CVE-2024-34473MEDIUM5.3An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message t...
CVE-2024-34468MEDIUM6.1Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.
CVE-2024-34467MEDIUM6.1ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_e...
CVE-2024-34462MEDIUM6.1Alinto SOGo through 5.10.0 allows XSS during attachment preview.
CVE-2024-1050MEDIUM4.3The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2024-34460MEDIUM6.5The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5...
CVE-2024-3237MEDIUM5.4The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2024-3868MEDIUM5.4The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name ...
CVE-2024-34453MEDIUM4.3TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity...
CVE-2024-34075MEDIUM6.2kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the ...
CVE-2024-34068MEDIUM6.4Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game serv...
CVE-2024-34067MEDIUM6.1Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg...
CVE-2024-33793MEDIUM5.3netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now