2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35627 | MEDIUM | 6.1 | 1.0% | May 22, 2024 | tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data... |
| CVE-2024-31904 | MEDIUM | 6.5 | 0.5% | May 22, 2024 | IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an au... |
| CVE-2024-31893 | MEDIUM | 4.3 | 0.3% | May 22, 2024 | IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar inf... |
| CVE-2024-25738 | CRITICAL | 9.1 | 0.7% | May 22, 2024 | A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0... |
| CVE-2024-25737 | MEDIUM | 5.4 | 0.4% | May 22, 2024 | A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open ... |
| CVE-2024-31617 | MEDIUM | 5.3 | 0.4% | May 22, 2024 | OpenLiteSpeed before 1.8.1 mishandles chunked encoding. |
| CVE-2024-29421 | MEDIUM | 6.2 | 0.2% | May 22, 2024 | xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to... |
| CVE-2024-21791 | HIGH | 7.2 | 2.2% | May 22, 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin user... |
| CVE-2024-20360 | HIGH | 8.8 | 0.8% | May 22, 2024 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an... |
| CVE-2024-5166 | MEDIUM | 6.5 | 0.2% | May 22, 2024 | An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users... |
| CVE-2024-4563 | HIGH | 7.5 | 0.2% | May 22, 2024 | The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insuffic... |
| CVE-2024-36077 | HIGH | 8.8 | 0.6% | May 22, 2024 | Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper va... |
| CVE-2024-20363 | MEDIUM | 5.8 | 0.4% | May 22, 2024 | Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that ... |
| CVE-2024-20361 | MEDIUM | 5.8 | 0.4% | May 22, 2024 | A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) ... |
| CVE-2024-20355 | MEDIUM | 5 | 0.3% | May 22, 2024 | A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive ... |
| CVE-2024-20293 | MEDIUM | 5.8 | 0.4% | May 22, 2024 | A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software an... |
| CVE-2024-20261 | MEDIUM | 5.8 | 0.4% | May 22, 2024 | A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Def... |
| CVE-2024-5160 | HIGH | 8.8 | 0.6% | May 22, 2024 | Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of boun... |
| CVE-2024-5159 | HIGH | 8.8 | 0.6% | May 22, 2024 | Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bou... |
| CVE-2024-5158 | HIGH | 8.1 | 0.6% | May 22, 2024 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary ... |
| CVE-2024-5157 | HIGH | 8.8 | 0.8% | May 22, 2024 | Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code... |
| CVE-2024-35362 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php. |
| CVE-2024-34448 | HIGH | 8.8 | 0.7% | May 22, 2024 | Ghost before 5.82.0 allows CSV Injection during a member CSV export. |
| CVE-2024-33228 | HIGH | 8.4 | 0.3% | May 22, 2024 | An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to ... |
| CVE-2024-33227 | HIGH | 8.8 | 0.5% | May 22, 2024 | An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now