2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5413MEDIUM6.1A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS...
CVE-2024-3657HIGH7.5A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server,...
CVE-2024-2199MEDIUM5.7A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to ca...
CVE-2024-28793MEDIUM5.4IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configur...
CVE-2024-5411HIGH8.8Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated...
CVE-2024-5410MEDIUM5.4Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects ...
CVE-2024-32944LOW3.3Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU ...
CVE-2024-28886HIGH8.4OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UT...
CVE-2024-29078HIGH7.5Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may al...
CVE-2024-28880MEDIUM6.5Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the prod...
CVE-2024-36428HIGH8.1OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.
CVE-2024-36426HIGH7.5In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a clea...
CVE-2024-34923MEDIUM6.1In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before...
CVE-2024-29415HIGH8.1The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2...
CVE-2024-35182HIGH8.1Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur...
CVE-2024-35181HIGH8.1Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur...
CVE-2024-36105MEDIUM5.3dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to ...
CVE-2024-36037MEDIUM5.5Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session...
CVE-2024-36036MEDIUM4.2Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive...
CVE-2024-35238MEDIUM5.3Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerab...
CVE-2024-27310MEDIUM6.5Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP inpu...
CVE-2024-35237HIGH7.5MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants ...
CVE-2024-35236MEDIUM4.8Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious s...
CVE-2024-35231HIGH8.6rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-...
CVE-2024-35229MEDIUM5.3ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a ve...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now