2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-21429MEDIUM6.8Windows USB Hub Driver Remote Code Execution Vulnerability
CVE-2024-21419MEDIUM5.4Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21408MEDIUM5.5Windows Hyper-V Denial of Service Vulnerability
CVE-2024-20671MEDIUM5.5Microsoft Defender Security Feature Bypass Vulnerability
CVE-2024-1529MEDIUM6.1Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-...
CVE-2024-1528MEDIUM6.1CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting ...
CVE-2024-1304MEDIUM6.1Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerab...
CVE-2024-1303MEDIUM6.5Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up ...
CVE-2024-1302MEDIUM5.5Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker...
CVE-2024-23112MEDIUM4.3An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2....
CVE-2024-21761MEDIUM4.3An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may...
CVE-2024-1227MEDIUM6.5An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a ...
CVE-2024-2049MEDIUM5.3Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 al...
CVE-2024-2391MEDIUM6.1A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown funct...
CVE-2024-22045MEDIUM6.5A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensit...
CVE-2024-21483MEDIUM5.1A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 o...
CVE-2024-2371MEDIUM6.2Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol ...
CVE-2024-27279MEDIUM6.5Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0....
CVE-2024-26005MEDIUM4.8An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restar...
CVE-2024-25997MEDIUM5.3An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file...
CVE-2024-25994MEDIUM5.3An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload desti...
CVE-2024-1328MEDIUM5.4The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all ver...
CVE-2024-0906MEDIUM5.3The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-24964MEDIUM6.3Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prio...
CVE-2024-21584MEDIUM6.1Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now