2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-55000MEDIUM5.4Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categori...
CVE-2024-39773MEDIUM5.3An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A ...
CVE-2024-39363MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC300...
CVE-2024-56497MEDIUM6.7An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail vers...
CVE-2024-54021MEDIUM5.8An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fort...
CVE-2024-52969MEDIUM6.5An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiS...
CVE-2024-52967MEDIUM4.8An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6...
CVE-2024-52963MEDIUM5.9A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.1...
CVE-2024-48893MEDIUM5.4An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, ...
CVE-2024-47566MEDIUM6A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder vers...
CVE-2024-46669MEDIUM6.5An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSAS...
CVE-2024-46666MEDIUM5.3An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4....
CVE-2024-46664MEDIUM4.9A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privi...
CVE-2024-45326MEDIUM4.3An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all ...
CVE-2024-40587MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-36510MEDIUM5.3An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version...
CVE-2024-36506MEDIUM5.3An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 thr...
CVE-2024-36504MEDIUM6.5An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 ...
CVE-2024-35278MEDIUM4.3A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions ...
CVE-2024-32115MEDIUM5.5A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 ...
CVE-2024-21758MEDIUM6.7A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri...
CVE-2024-11863MEDIUM5.3Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may l...
CVE-2024-45385MEDIUM6.1A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vu...
CVE-2024-12240MEDIUM5.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label param...
CVE-2024-13156MEDIUM6.4The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now