2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35627MEDIUM6.1tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data...
CVE-2024-31904MEDIUM6.5IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an au...
CVE-2024-31893MEDIUM4.3IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar inf...
CVE-2024-25738CRITICAL9.1A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0...
CVE-2024-25737MEDIUM5.4A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open ...
CVE-2024-31617MEDIUM5.3OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
CVE-2024-29421MEDIUM6.2xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to...
CVE-2024-21791HIGH7.2Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin user...
CVE-2024-20360HIGH8.8A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an...
CVE-2024-5166MEDIUM6.5An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users...
CVE-2024-4563HIGH7.5The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insuffic...
CVE-2024-36077HIGH8.8Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper va...
CVE-2024-20363MEDIUM5.8Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that ...
CVE-2024-20361MEDIUM5.8A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) ...
CVE-2024-20355MEDIUM5A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive ...
CVE-2024-20293MEDIUM5.8A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software an...
CVE-2024-20261MEDIUM5.8A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Def...
CVE-2024-5160HIGH8.8Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of boun...
CVE-2024-5159HIGH8.8Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bou...
CVE-2024-5158HIGH8.1Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary ...
CVE-2024-5157HIGH8.8Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code...
CVE-2024-35362MEDIUM5.4Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.
CVE-2024-34448HIGH8.8Ghost before 5.82.0 allows CSV Injection during a member CSV export.
CVE-2024-33228HIGH8.4An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to ...
CVE-2024-33227HIGH8.8An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now