2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55000 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categori... |
| CVE-2024-39773 | MEDIUM | 5.3 | 0.8% | Jan 14, 2025 | An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A ... |
| CVE-2024-39363 | MEDIUM | 6.1 | 48.1% | Jan 14, 2025 | A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC300... |
| CVE-2024-56497 | MEDIUM | 6.7 | 0.6% | Jan 14, 2025 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail vers... |
| CVE-2024-54021 | MEDIUM | 5.8 | 0.8% | Jan 14, 2025 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fort... |
| CVE-2024-52969 | MEDIUM | 6.5 | 0.5% | Jan 14, 2025 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiS... |
| CVE-2024-52967 | MEDIUM | 4.8 | 0.3% | Jan 14, 2025 | An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6... |
| CVE-2024-52963 | MEDIUM | 5.9 | 0.7% | Jan 14, 2025 | A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.1... |
| CVE-2024-48893 | MEDIUM | 5.4 | 0.4% | Jan 14, 2025 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, ... |
| CVE-2024-47566 | MEDIUM | 6 | 0.2% | Jan 14, 2025 | A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder vers... |
| CVE-2024-46669 | MEDIUM | 6.5 | 0.6% | Jan 14, 2025 | An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSAS... |
| CVE-2024-46666 | MEDIUM | 5.3 | 0.7% | Jan 14, 2025 | An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.... |
| CVE-2024-46664 | MEDIUM | 4.9 | 0.5% | Jan 14, 2025 | A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privi... |
| CVE-2024-45326 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all ... |
| CVE-2024-40587 | MEDIUM | 6.7 | 0.6% | Jan 14, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-36510 | MEDIUM | 5.3 | 0.7% | Jan 14, 2025 | An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version... |
| CVE-2024-36506 | MEDIUM | 5.3 | 0.5% | Jan 14, 2025 | An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 thr... |
| CVE-2024-36504 | MEDIUM | 6.5 | 0.7% | Jan 14, 2025 | An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 ... |
| CVE-2024-35278 | MEDIUM | 4.3 | 0.4% | Jan 14, 2025 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions ... |
| CVE-2024-32115 | MEDIUM | 5.5 | 1.0% | Jan 14, 2025 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 ... |
| CVE-2024-21758 | MEDIUM | 6.7 | 0.2% | Jan 14, 2025 | A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri... |
| CVE-2024-11863 | MEDIUM | 5.3 | 0.4% | Jan 14, 2025 | Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may l... |
| CVE-2024-45385 | MEDIUM | 6.1 | 0.3% | Jan 14, 2025 | A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vu... |
| CVE-2024-12240 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label param... |
| CVE-2024-13156 | MEDIUM | 6.4 | 0.3% | Jan 14, 2025 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now