2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11920MEDIUM4.3Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform...
CVE-2024-11919MEDIUM4.3Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to ...
CVE-2024-48829MEDIUM6.7Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Inj...
CVE-2024-45301MEDIUM5.3Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can c...
CVE-2024-32014MEDIUM5.6A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i...
CVE-2024-13998MEDIUM6.5Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (includ...
CVE-2024-51317MEDIUM6.5An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function
CVE-2024-13992MEDIUM5.4Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing pag...
CVE-2024-14006MEDIUM6.1Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-su...
CVE-2024-14002MEDIUM5.5Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An...
CVE-2024-14001MEDIUM5.4Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report com...
CVE-2024-14000MEDIUM5.4Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report com...
CVE-2024-13993MEDIUM6.1Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page whe...
CVE-2024-58269MEDIUM4.3A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster imp...
CVE-2024-45161MEDIUM4.6A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via...
CVE-2024-31573MEDIUM4XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (us...
CVE-2024-42192MEDIUM5.5HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access...
CVE-2024-47569MEDIUM4.3A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7...
CVE-2024-26008MEDIUM5.3An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 a...
CVE-2024-44088MEDIUM6.1Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability all...
CVE-2024-57494MEDIUM6.5Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalat...
CVE-2024-5200MEDIUM4.8The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-58241MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregiste...
CVE-2024-21935MEDIUM5Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate R...
CVE-2024-21927MEDIUM5Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now