2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-43181MEDIUM6.3IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impe...
CVE-2024-40685MEDIUM4.3IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are...
CVE-2024-39724MEDIUM5.3IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper...
CVE-2024-4147MEDIUM6.5In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p...
CVE-2024-9432MEDIUM6.9Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data.  ...
CVE-2024-54855MEDIUM6.4fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attac...
CVE-2024-14020MEDIUM5A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unkn...
CVE-2024-31088MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru A...
CVE-2024-23511MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH Th...
CVE-2024-55374MEDIUM5.3REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.
CVE-2024-42718MEDIUM6.5A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially craft...
CVE-2024-29720MEDIUM5.5An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via...
CVE-2024-40317MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in...
CVE-2024-39037MEDIUM6.5MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu paramete...
CVE-2024-35322MEDIUM6.1MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro param...
CVE-2024-58335MEDIUM5OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not...
CVE-2024-25812MEDIUM6.1MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.
CVE-2024-35321MEDIUM4.3MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parame...
CVE-2024-25814MEDIUM6.1MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.
CVE-2024-58323MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Ch...
CVE-2024-58322MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping...
CVE-2024-58321MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form v...
CVE-2024-58320MEDIUM6.9An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration inte...
CVE-2024-58319MEDIUM6.1A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the...
CVE-2024-58318MEDIUM6.1A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the ri...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now