2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-29892MEDIUM4.9ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circums...
CVE-2024-29888MEDIUM5.4Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-coll...
CVE-2024-29886MEDIUM5.3Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old passw...
CVE-2024-28860MEDIUM6.8Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent en...
CVE-2024-28247MEDIUM6.5The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side softwa...
CVE-2024-28233MEDIUM6.1JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdo...
CVE-2024-23451MEDIUM6.5Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently...
CVE-2024-20333MEDIUM4.3A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow a...
CVE-2024-20324MEDIUM5.5A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to acce...
CVE-2024-20316MEDIUM5.3A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remo...
CVE-2024-20309MEDIUM5.5A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, lo...
CVE-2024-20306MEDIUM6.7A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authentica...
CVE-2024-20278MEDIUM6.5A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate...
CVE-2024-20265MEDIUM5.9A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacke...
CVE-2024-29765MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alireza Sedghi Apa...
CVE-2024-29764MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molongui allows St...
CVE-2024-29763MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPre...
CVE-2024-29762MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jory Hogeveen Off-...
CVE-2024-29761MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Krunal Prajapati W...
CVE-2024-29760MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Boost...
CVE-2024-29759MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calcula...
CVE-2024-28853MEDIUM5.9Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerabili...
CVE-2024-28852MEDIUM6.1Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabi...
CVE-2024-26652MEDIUM4.1In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error ha...
CVE-2024-26651MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sr9800: Add check for usbnet_get_endpoints Add che...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now