2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-14044 | MEDIUM | 6.3 | — | Aug 12, 2026 | A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc... |
| CVE-2024-14043 | MEDIUM | 6.3 | — | Aug 12, 2026 | A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data... |
| CVE-2024-14042 | MEDIUM | 6.3 | — | Aug 11, 2026 | A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr... |
| CVE-2024-6541 | MEDIUM | 6.8 | 0.3% | Aug 6, 2026 | The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy... |
| CVE-2024-8995 | MEDIUM | 4.9 | 0.1% | Aug 6, 2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a... |
| CVE-2024-10302 | MEDIUM | 5.8 | 0.2% | Aug 6, 2026 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo... |
| CVE-2024-40683 | MEDIUM | 6.3 | — | Jul 30, 2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,... |
| CVE-2024-5300 | MEDIUM | 5.6 | — | Jul 21, 2026 | An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura... |
| CVE-2024-58370 | MEDIUM | 6.5 | 0.3% | Jul 18, 2026 | SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin... |
| CVE-2024-58364 | MEDIUM | 6.5 | 0.2% | Jul 18, 2026 | SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer... |
| CVE-2024-58363 | MEDIUM | 6.3 | 0.2% | Jul 18, 2026 | SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clau... |
| CVE-2024-58358 | MEDIUM | 6.9 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owne... |
| CVE-2024-42214 | MEDIUM | 5.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method ... |
| CVE-2024-23578 | MEDIUM | 4.2 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) ... |
| CVE-2024-23577 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary... |
| CVE-2024-23575 | MEDIUM | 5.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information ... |
| CVE-2024-23574 | MEDIUM | 5.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to ... |
| CVE-2024-23572 | MEDIUM | 4.2 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as... |
| CVE-2024-23571 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying... |
| CVE-2024-23570 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta... |
| CVE-2024-23569 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header |
| CVE-2024-23568 | MEDIUM | 5.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th... |
| CVE-2024-23567 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti... |
| CVE-2024-23566 | MEDIUM | 6.5 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead... |
| CVE-2024-23565 | MEDIUM | 5.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now