2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-21866MEDIUM5.3In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error me...
CVE-2024-21794MEDIUM5.4In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages t...
CVE-2024-23034MEDIUM6.1Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary c...
CVE-2024-23033MEDIUM6.1Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary co...
CVE-2024-23032MEDIUM6.1Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code vi...
CVE-2024-23031MEDIUM6.1Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitr...
CVE-2024-22927MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitr...
CVE-2024-24755MEDIUM5.3discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP...
CVE-2024-1040MEDIUM4.4Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by...
CVE-2024-24945MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows att...
CVE-2024-24041MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows att...
CVE-2024-24569MEDIUM4.8The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurre...
CVE-2024-23645MEDIUM6.1GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. U...
CVE-2024-24570MEDIUM6.1Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing f...
CVE-2024-24753MEDIUM6.5Bref enable serverless PHP on AWS Lambda. When Bref is used in combination with an API Gateway with the v2 format, it do...
CVE-2024-24752MEDIUM6.5Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a ...
CVE-2024-1141MEDIUM5.5A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-s...
CVE-2024-24062MEDIUM5.4springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.
CVE-2024-24061MEDIUM5.4springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.
CVE-2024-24060MEDIUM5.4springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.
CVE-2024-24059MEDIUM5.4springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded file...
CVE-2024-22430MEDIUM5.5 Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local l...
CVE-2024-22148MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Editor Jo...
CVE-2024-21750MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scribit Shortcodes...
CVE-2024-24548MEDIUM6.5Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now