2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5413 | MEDIUM | 6.1 | 0.3% | May 28, 2024 | A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS... |
| CVE-2024-3657 | HIGH | 7.5 | 1.3% | May 28, 2024 | A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server,... |
| CVE-2024-2199 | MEDIUM | 5.7 | 0.5% | May 28, 2024 | A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to ca... |
| CVE-2024-28793 | MEDIUM | 5.4 | 0.3% | May 28, 2024 | IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configur... |
| CVE-2024-5411 | HIGH | 8.8 | 23.4% | May 28, 2024 | Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated... |
| CVE-2024-5410 | MEDIUM | 5.4 | 13.2% | May 28, 2024 | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects ... |
| CVE-2024-32944 | LOW | 3.3 | 0.2% | May 28, 2024 | Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU ... |
| CVE-2024-28886 | HIGH | 8.4 | 0.7% | May 28, 2024 | OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UT... |
| CVE-2024-29078 | HIGH | 7.5 | 0.4% | May 28, 2024 | Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may al... |
| CVE-2024-28880 | MEDIUM | 6.5 | 0.6% | May 28, 2024 | Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the prod... |
| CVE-2024-36428 | HIGH | 8.1 | 1.7% | May 27, 2024 | OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection. |
| CVE-2024-36426 | HIGH | 7.5 | 0.3% | May 27, 2024 | In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a clea... |
| CVE-2024-34923 | MEDIUM | 6.1 | 0.3% | May 27, 2024 | In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before... |
| CVE-2024-29415 | HIGH | 8.1 | 8.3% | May 27, 2024 | The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2... |
| CVE-2024-35182 | HIGH | 8.1 | 1.6% | May 27, 2024 | Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur... |
| CVE-2024-35181 | HIGH | 8.1 | 1.6% | May 27, 2024 | Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur... |
| CVE-2024-36105 | MEDIUM | 5.3 | 0.7% | May 27, 2024 | dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to ... |
| CVE-2024-36037 | MEDIUM | 5.5 | 0.5% | May 27, 2024 | Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session... |
| CVE-2024-36036 | MEDIUM | 4.2 | 0.4% | May 27, 2024 | Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive... |
| CVE-2024-35238 | MEDIUM | 5.3 | 0.5% | May 27, 2024 | Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerab... |
| CVE-2024-27310 | MEDIUM | 6.5 | 2.3% | May 27, 2024 | Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP inpu... |
| CVE-2024-35237 | HIGH | 7.5 | 0.5% | May 27, 2024 | MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants ... |
| CVE-2024-35236 | MEDIUM | 4.8 | 0.8% | May 27, 2024 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious s... |
| CVE-2024-35231 | HIGH | 8.6 | 0.7% | May 27, 2024 | rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-... |
| CVE-2024-35229 | MEDIUM | 5.3 | 0.4% | May 27, 2024 | ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a ve... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now