2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-2204MEDIUM5.5Zemana AntiLogger v2.74.204.664 is vulnerable to a Denial of Service (DoS) vulnerability by triggering the 0x80002004 an...
CVE-2024-2180MEDIUM5.5Zemana AntiLogger v2.74.204.664 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x80002020 IO...
CVE-2024-26454MEDIUM5.4A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1...
CVE-2024-26163MEDIUM4.7Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2024-1853MEDIUM5.5Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x8000...
CVE-2024-2249MEDIUM5.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWr...
CVE-2024-26475MEDIUM5.5An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of ...
CVE-2024-2256MEDIUM5.4The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact...
CVE-2024-27265MEDIUM6.5IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an atta...
CVE-2024-24770MEDIUM5.3vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le...
CVE-2024-24562MEDIUM5.3vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers ar...
CVE-2024-23823MEDIUM6.5vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le...
CVE-2024-28849MEDIUM6.5follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows...
CVE-2024-28323MEDIUM6.5The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a pot...
CVE-2024-25156MEDIUM6.5 A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-sp...
CVE-2024-28418MEDIUM6.5Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
CVE-2024-28417MEDIUM6.3Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
CVE-2024-27986MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor...
CVE-2024-0313MEDIUM5.5A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organiza...
CVE-2024-0312MEDIUM5.5A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.
CVE-2024-0311MEDIUM5.5A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.
CVE-2024-22398MEDIUM4.9An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Securit...
CVE-2024-22396MEDIUM5.3An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ...
CVE-2024-1884MEDIUM6.5This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an atta...
CVE-2024-1883MEDIUM6.1This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now