2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-48893MEDIUM5.4An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, ...
CVE-2024-47566MEDIUM6A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder vers...
CVE-2024-46669MEDIUM6.5An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSAS...
CVE-2024-46666MEDIUM5.3An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4....
CVE-2024-46664MEDIUM4.9A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privi...
CVE-2024-45326MEDIUM4.3An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all ...
CVE-2024-40587MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2024-36510MEDIUM5.3An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version...
CVE-2024-36506MEDIUM5.3An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 thr...
CVE-2024-36504MEDIUM6.5An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 ...
CVE-2024-35278MEDIUM4.3A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions ...
CVE-2024-32115MEDIUM5.5A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 ...
CVE-2024-21758MEDIUM6.7A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri...
CVE-2024-11863MEDIUM5.3Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may l...
CVE-2024-45385MEDIUM6.1A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vu...
CVE-2024-12240MEDIUM5.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label param...
CVE-2024-13156MEDIUM6.4The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-...
CVE-2024-11736MEDIUM4.9A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system ...
CVE-2024-11734MEDIUM6.5A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change...
CVE-2024-12006MEDIUM5.3The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2024-13323MEDIUM5.4The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' sho...
CVE-2024-12298MEDIUM5.5We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attac...
CVE-2024-12083MEDIUM6.6Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these ...
CVE-2024-11396MEDIUM5.3The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information ...
CVE-2024-56138MEDIUM4notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specificati...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now