2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29830 | HIGH | 8 | 8.5% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac... |
| CVE-2024-29829 | HIGH | 8 | 8.2% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac... |
| CVE-2024-29828 | HIGH | 8 | 8.5% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac... |
| CVE-2024-29827 | HIGH | 8.8 | 71.7% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29826 | HIGH | 8.8 | 99.9% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29825 | HIGH | 8.8 | 99.9% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29824 | HIGH | 8.8 | 100.0% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29823 | HIGH | 8.8 | 99.9% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29822 | HIGH | 8.8 | 64.4% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-22060 | MEDIUM | 4.9 | 1.1% | May 31, 2024 | An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, hi... |
| CVE-2024-22059 | HIGH | 8.8 | 1.1% | May 31, 2024 | A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/mod... |
| CVE-2024-22058 | HIGH | 7.8 | 0.4% | May 31, 2024 | A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary... |
| CVE-2024-1275 | CRITICAL | 9.1 | 0.4% | May 31, 2024 | Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environ... |
| CVE-2024-36120 | HIGH | 7.8 | 0.3% | May 31, 2024 | javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targetin... |
| CVE-2024-35142 | HIGH | 7.8 | 0.2% | May 31, 2024 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to exe... |
| CVE-2024-35140 | HIGH | 7.8 | 0.1% | May 31, 2024 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to imp... |
| CVE-2024-28736 | HIGH | 7.1 | 2.5% | May 31, 2024 | An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page ... |
| CVE-2024-5565 | HIGH | 8.1 | 15.0% | May 31, 2024 | The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt... |
| CVE-2024-36108 | CRITICAL | 9.8 | 0.6% | May 31, 2024 | casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenti... |
| CVE-2024-1980 | — | — | — | May 31, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6876. Reason: This candidate is a r... |
| CVE-2024-31908 | MEDIUM | 5.4 | 0.2% | May 31, 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users t... |
| CVE-2024-31907 | MEDIUM | 5.4 | 0.2% | May 31, 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2024-31889 | MEDIUM | 5.4 | 0.2% | May 31, 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2024-5538 | — | — | — | May 31, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5484 | — | — | — | May 31, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now