2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-31027MEDIUM5.4Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote att...
CVE-2024-58386MEDIUM6.5ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authentica...
CVE-2024-56344MEDIUM5.9IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain se...
CVE-2024-38639MEDIUM4.8An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the ...
CVE-2024-27123MEDIUM5.2A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit t...
CVE-2024-11222MEDIUM6.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1...
CVE-2024-58384MEDIUM5.4Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return...
CVE-2024-23176MEDIUM5.4An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss...
CVE-2024-53922MEDIUM5.7An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. L...
CVE-2024-12145MEDIUM4.3The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi...
CVE-2024-58380MEDIUM6.5PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes t...
CVE-2024-3773MEDIUM5.9The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes b...
CVE-2024-58379MEDIUM5.3nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUr...
CVE-2024-58376MEDIUM6.7Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAli...
CVE-2024-14046MEDIUM6.3A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController ...
CVE-2024-14045MEDIUM6.3A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/...
CVE-2024-14044MEDIUM6.3A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc...
CVE-2024-14043MEDIUM6.3A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data...
CVE-2024-14042MEDIUM6.3A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr...
CVE-2024-6541MEDIUM6.8The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy...
CVE-2024-8995MEDIUM4.9Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a...
CVE-2024-10302MEDIUM5.8The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo...
CVE-2024-40683MEDIUM6.3IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,...
CVE-2024-14041MEDIUM5.9In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno...
CVE-2024-5300MEDIUM5.6An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now