2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-28949MEDIUM6.5Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit t...
CVE-2024-27437MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Disable auto-enable of exclusive INTx IRQ...
CVE-2024-26814MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vfio/fsl-mc: Block calling interrupt handler withou...
CVE-2024-26813MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vfio/platform: Create persistent IRQ handlers The ...
CVE-2024-26812MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Create persistent INTx handler A vulnera...
CVE-2024-26329MEDIUM6.2Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBy...
CVE-2024-2509MEDIUM6.5The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block opt...
CVE-2024-3321MEDIUM4.8A vulnerability classified as problematic has been found in SourceCodester eLearning System 1.0. This affects an unknown...
CVE-2024-3320MEDIUM6.1A vulnerability was found in SourceCodester eLearning System 1.0. It has been rated as problematic. Affected by this iss...
CVE-2024-29981MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-29049MEDIUM4.7Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
CVE-2024-31204MEDIUM6.1mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie...
CVE-2024-30270MEDIUM6.2mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie...
CVE-2024-29386MEDIUM5.4projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceE...
CVE-2024-24795MEDIUM6.3HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response ...
CVE-2024-22023MEDIUM5.3An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Se...
CVE-2024-30254MEDIUM5.8MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1...
CVE-2024-29193MEDIUM6.1gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. Th...
CVE-2024-2660MEDIUM6.8Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP ...
CVE-2024-25709MEDIUM6.1There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may al...
CVE-2024-25708MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9....
CVE-2024-25706MEDIUM6.1There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticat...
CVE-2024-25705MEDIUM5.4There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below...
CVE-2024-25700MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 ...
CVE-2024-25698MEDIUM6.1There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now