2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-24683MEDIUM6.5Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users ...
CVE-2024-25942MEDIUM6.8Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high pri...
CVE-2024-22453MEDIUM6Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could p...
CVE-2024-24043MEDIUM5.5Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary co...
CVE-2024-0055MEDIUM6.5Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was...
CVE-2024-0054MEDIUM6.5Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi...
CVE-2024-28447MEDIUM6.5Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_ipaddr pa...
CVE-2024-28446MEDIUM5.7Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_netmask p...
CVE-2024-22025MEDIUM6.5A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustio...
CVE-2024-21504MEDIUM6.1Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when ...
CVE-2024-21503MEDIUM5.3Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines...
CVE-2024-28855MEDIUM6.1ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use...
CVE-2024-28250MEDIUM6.1Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 an...
CVE-2024-28249MEDIUM6.1Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1....
CVE-2024-28237MEDIUM4.8OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.9.3...
CVE-2024-23333MEDIUM6.6LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration al...
CVE-2024-22412MEDIUM4.9ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering p...
CVE-2024-25657MEDIUM5.4An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07...
CVE-2024-25656MEDIUM5.9Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated ...
CVE-2024-25655MEDIUM6.5Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23....
CVE-2024-25654MEDIUM5.5Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with l...
CVE-2024-0973MEDIUM6.1The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which co...
CVE-2024-0951MEDIUM4.8The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its setti...
CVE-2024-0820MEDIUM5.4The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a ...
CVE-2024-0719MEDIUM5.4The Tabs Shortcode and Widget WordPress plugin through 1.17 does not validate and escape some of its shortcode attribute...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now