2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38207MEDIUM6.3Microsoft Edge (HTML-based) Memory Corruption Vulnerability
CVE-2024-40111MEDIUM4.8A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulner...
CVE-2024-37392MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerabil...
CVE-2024-45190MEDIUM6.5Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal ...
CVE-2024-45189MEDIUM6.5Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal ...
CVE-2024-45188MEDIUM6.5Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal ...
CVE-2024-45187HIGH8.8Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high p...
CVE-2024-42914CRITICAL9.1A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending ...
CVE-2024-42845HIGH8An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 al...
CVE-2024-7954CRITICAL9.8The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution ...
CVE-2024-42992Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-42852MEDIUM6.1Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary cod...
CVE-2024-7428MEDIUM4.8URL Redirection to Untrusted Site ('Open Redirect') vulnerability in OpenText™ Network Node Manager i (NNMi) allows URL ...
CVE-2024-7427MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ N...
CVE-2024-44390HIGH8.8Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.
CVE-2024-44387MEDIUM6.5Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.
CVE-2024-43794MEDIUM6.1OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSea...
CVE-2024-42918MEDIUM5.4itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attac...
CVE-2024-42531CRITICAL9.8Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a...
CVE-2024-41878MEDIUM5.4Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-41877MEDIUM5.4Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-41876MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-41875MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-41849MEDIUM4.1Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou...
CVE-2024-41848MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now