2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-32037MEDIUM5.3GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the...
CVE-2024-12833MEDIUM6.1Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows n...
CVE-2024-40586MEDIUM6.7An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, versio...
CVE-2024-36508MEDIUM6An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2024-27780MEDIUM5.4Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] i...
CVE-2024-12756MEDIUM6.1An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of ...
CVE-2024-12755MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential di...
CVE-2024-13843MEDIUM4.4Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before versio...
CVE-2024-13842MEDIUM4.4A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows...
CVE-2024-13830MEDIUM6.1Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a...
CVE-2024-12797MEDIUM6.3Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server ...
CVE-2024-12058MEDIUM4.9External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version...
CVE-2024-11771MEDIUM5.3Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted function...
CVE-2024-54090MEDIUM6A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2024-53651MEDIUM5.1A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),...
CVE-2024-23814MEDIUM6.9The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory reso...
CVE-2024-13506MEDIUM6.4The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2024-52612MEDIUM4.8SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient ...
CVE-2024-45718MEDIUM4.6Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a l...
CVE-2024-28989MEDIUM5.5SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive in...
CVE-2024-13570MEDIUM6.1The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-13544MEDIUM4.8The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privile...
CVE-2024-13543MEDIUM6.1The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-12599MEDIUM6.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-57178MEDIUM5.9An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' pa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now