2024 CVE Vulnerabilities

39,152 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-6156LOW3.8Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was prese...
CVE-2024-54140LOW2.1sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver...
CVE-2024-38829LOW3.7A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from ...
CVE-2024-12056LOW2.3The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacke...
CVE-2024-53502LOW3.8Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
CVE-2024-53921LOW2.8An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders ...
CVE-2024-25036LOW3.3IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security all...
CVE-2024-49417LOW3.3Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch...
CVE-2024-49414LOW2.4Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to t...
CVE-2024-53988LOW2.3rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53987LOW2.3rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53986LOW2.3rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53985LOW2.3rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53989LOW2.3rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-11856LOW3.7A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.
CVE-2024-52800LOW2.3veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI in...
CVE-2024-46939LOW2.4The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameter...
CVE-2024-36464LOW2.7When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type...
CVE-2024-42333LOW2.7The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read...
CVE-2024-42332LOW3.7The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with addit...
CVE-2024-42331LOW3.3In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript...
CVE-2024-42329LOW3.3The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function...
CVE-2024-52008LOW2Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password...
CVE-2024-22117LOW2.2When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the s...
CVE-2024-8160LOW2.7Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficie...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now