2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-26247MEDIUM4.7Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2024-2824MEDIUM6.3A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function Prin...
CVE-2024-2823MEDIUM4.3A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of ...
CVE-2024-2822MEDIUM4.3A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file...
CVE-2024-29186MEDIUM5.3Bref is an open-source project that helps users go serverless on Amazon Web Services with PHP. When Bref prior to versio...
CVE-2024-29042MEDIUM5.3Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to ver...
CVE-2024-2821MEDIUM4.3A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. Affected by this issue is some unkn...
CVE-2024-2820MEDIUM4.3A vulnerability classified as problematic was found in DedeCMS 5.7. Affected by this vulnerability is an unknown functio...
CVE-2024-29865MEDIUM5.4Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
CVE-2024-28593MEDIUM5.4The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTM...
CVE-2024-2728MEDIUM5.5Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept t...
CVE-2024-2727MEDIUM6.1HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify ...
CVE-2024-2726MEDIUM6.1Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and...
CVE-2024-28560MEDIUM5.4SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the delete...
CVE-2024-25168MEDIUM6.3SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope pa...
CVE-2024-0638MEDIUM6.7Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b...
CVE-2024-2817MEDIUM6.5A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. Affected by this issue i...
CVE-2024-2816MEDIUM6.5A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. Affected by this vulnerability is the fun...
CVE-2024-29273MEDIUM6.1There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload ...
CVE-2024-29272MEDIUM6.5Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute ...
CVE-2024-29271MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute a...
CVE-2024-26557MEDIUM5.4Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.
CVE-2024-25807MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain s...
CVE-2024-2780MEDIUM6.1A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been declared as problematic. Thi...
CVE-2024-2500MEDIUM6.4The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now