2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45102MEDIUM6.8A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their ...
CVE-2024-10254MEDIUM4.7A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could al...
CVE-2024-10253MEDIUM4.7A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a loc...
CVE-2024-55945MEDIUM6.5TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55923MEDIUM4.3TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55922MEDIUM5.4TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55920MEDIUM4.3TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55894MEDIUM5.4TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55893MEDIUM4.3TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in...
CVE-2024-55892MEDIUM6.1TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse e...
CVE-2024-55891MEDIUM5.3TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has ...
CVE-2024-50349MEDIUM4.7Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2024-12747MEDIUM5.6A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rs...
CVE-2024-12086MEDIUM6.8A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's mach...
CVE-2024-53563MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to ex...
CVE-2024-52898MEDIUM6.2IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a ...
CVE-2024-45627MEDIUM5.9In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql J...
CVE-2024-55000MEDIUM5.4Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categori...
CVE-2024-39773MEDIUM5.3An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A ...
CVE-2024-39363MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC300...
CVE-2024-56497MEDIUM6.7An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail vers...
CVE-2024-54021MEDIUM5.8An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fort...
CVE-2024-52969MEDIUM6.5An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiS...
CVE-2024-52967MEDIUM4.8An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6...
CVE-2024-52963MEDIUM5.9A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.1...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now