2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-27968MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue...
CVE-2024-27965MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnel...
CVE-2024-27963MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Store...
CVE-2024-27962MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan...
CVE-2024-27277MEDIUM5.5The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining...
CVE-2024-2464MEDIUM6.3This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the u...
CVE-2024-29244MEDIUM5.3Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3...
CVE-2024-27995MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems...
CVE-2024-2494MEDIUM6.2A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays bef...
CVE-2024-29879MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/...
CVE-2024-29878MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'descrip...
CVE-2024-29877MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/e...
CVE-2024-28834MEDIUM5.3A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in ...
CVE-2024-26643MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: mark set as dead when unbindi...
CVE-2024-26642MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with t...
CVE-2024-26307MEDIUM5.3Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of ...
CVE-2024-29133MEDIUM5.4Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from ...
CVE-2024-28835MEDIUM5A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially cra...
CVE-2024-28635MEDIUM6.1Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute ar...
CVE-2024-22724MEDIUM6.6An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrar...
CVE-2024-2713MEDIUM6.5A vulnerability, which was classified as critical, was found in Campcodes Complete Online DJ Booking System 1.0. Affecte...
CVE-2024-2712MEDIUM6.5A vulnerability, which was classified as critical, has been found in Campcodes Complete Online DJ Booking System 1.0. Th...
CVE-2024-28102MEDIUM6.8JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can ...
CVE-2024-27936MEDIUM6.5Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to ...
CVE-2024-27932MEDIUM4.6Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now