2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25653MEDIUM4.3Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unli...
CVE-2024-25651MEDIUM5.3User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attack...
CVE-2024-25649MEDIUM6.7In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machin...
CVE-2024-1223MEDIUM4.8This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker...
CVE-2024-25650MEDIUM5.9Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator...
CVE-2024-2242MEDIUM6.1The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter i...
CVE-2024-2079MEDIUM5.4The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2024-27703MEDIUM5.4Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do ti...
CVE-2024-28662MEDIUM5.4A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag...
CVE-2024-28193MEDIUM6.5your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to creat...
CVE-2024-28192MEDIUM5.3your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQ...
CVE-2024-28175MEDIUM5.4Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of...
CVE-2024-27097MEDIUM5.3A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This...
CVE-2024-24693MEDIUM5.5Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authentica...
CVE-2024-24692MEDIUM4.7Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user ...
CVE-2024-2431MEDIUM5.5An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in c...
CVE-2024-2403MEDIUM5.9 Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Wi...
CVE-2024-28196MEDIUM6.1your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent oth...
CVE-2024-27953MEDIUM4.7Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affect...
CVE-2024-27952MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced...
CVE-2024-20322MEDIUM5.8A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco I...
CVE-2024-20319MEDIUM4.3A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to...
CVE-2024-20315MEDIUM5.8A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR ...
CVE-2024-20266MEDIUM5.3A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, r...
CVE-2024-20262MEDIUM6.5A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now