2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35106MEDIUM4.6NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability all...
CVE-2024-10383MEDIUM6.1An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions pri...
CVE-2024-13841MEDIUM4.3The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to In...
CVE-2024-13492MEDIUM6.1The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back...
CVE-2024-53586MEDIUM5.3An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra...
CVE-2024-48589MEDIUM6.3Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code vi...
CVE-2024-25883MEDIUM5.3The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.
CVE-2024-57673MEDIUM5.5An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Lin...
CVE-2024-57672MEDIUM5.5An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topolo...
CVE-2024-52892MEDIUM6.1IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2024-47256MEDIUM6Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to rea...
CVE-2024-13417MEDIUM4.6Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it ...
CVE-2024-57523MEDIUM4.5Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attacke...
CVE-2024-13416MEDIUM4.3Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system...
CVE-2024-36557MEDIUM6.6The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Fo...
CVE-2024-57599MEDIUM4.8Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a cra...
CVE-2024-57429MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2....
CVE-2024-57427MEDIUM6.1PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improper...
CVE-2024-43779MEDIUM6.5An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. ...
CVE-2024-13614MEDIUM5.3Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Ligh...
CVE-2024-49800MEDIUM6.5IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.
CVE-2024-49798MEDIUM4.3IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message i...
CVE-2024-49797MEDIUM5.9IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable...
CVE-2024-49796MEDIUM5.4IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi...
CVE-2024-49795MEDIUM4.3IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now