2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-58317MEDIUM6.9A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when sett...
CVE-2024-29370MEDIUM5.3In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) c...
CVE-2024-58302MEDIUM6.9FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrar...
CVE-2024-58297MEDIUM5.4PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows att...
CVE-2024-58296MEDIUM5.3CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allow...
CVE-2024-58292MEDIUM5.3XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to...
CVE-2024-58291MEDIUM5.3Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject ma...
CVE-2024-58289MEDIUM5.4Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal...
CVE-2024-42197MEDIUM5.5HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.
CVE-2024-40593MEDIUM4.4A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, ...
CVE-2024-58285MEDIUM5.4Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scr...
CVE-2024-2105MEDIUM6.5An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to dead...
CVE-2024-47570MEDIUM6.6An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 throug...
CVE-2024-38798MEDIUM5.8EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized ...
CVE-2024-9183MEDIUM6.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, a...
CVE-2024-49572MEDIUM6.5A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special...
CVE-2024-32388MEDIUM5.3Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP...
CVE-2024-5540MEDIUM6.9The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affec...
CVE-2024-8528MEDIUM5.4Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload d...
CVE-2024-44664MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and ...
CVE-2024-44661MEDIUM5.4PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart....
CVE-2024-46335MEDIUM4.6PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parame...
CVE-2024-44663MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
CVE-2024-44662MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
CVE-2024-44660MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now