2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-26466MEDIUM6.1A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform...
CVE-2024-26465MEDIUM6.1A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before...
CVE-2024-25763MEDIUM5.5openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.
CVE-2024-25410MEDIUM6.5flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.
CVE-2024-25344MEDIUM6.1Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remto...
CVE-2024-25082MEDIUM6.5Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
CVE-2024-25081MEDIUM4.2Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
CVE-2024-24568MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P...
CVE-2024-1890MEDIUM5.4Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote att...
CVE-2024-1871MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. Affect...
CVE-2024-1436MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, S...
CVE-2024-1165MEDIUM6.5The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,...
CVE-2024-0798MEDIUM6.5A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete ...
CVE-2024-0440MEDIUM6.5Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protoco...
CVE-2024-0436MEDIUM5.9Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password ...
CVE-2024-0435MEDIUM5.4User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page lo...
CVE-2024-0387MEDIUM6.5The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An atta...
CVE-2024-21501MEDIUM5.3Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and ...
CVE-2024-1810MEDIUM6.1The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s...
CVE-2024-22395MEDIUM6.3Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific...
CVE-2024-26188MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-21423MEDIUM4.8Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-1834MEDIUM6.1A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as problematic....
CVE-2024-1825MEDIUM6.1A vulnerability, which was classified as problematic, was found in CodeAstro House Rental Management System 1.0. This af...
CVE-2024-1823MEDIUM5.3A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now