2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3485HIGH7.5Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senst...
CVE-2024-3484CRITICAL9.8Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.
CVE-2024-3483CRITICAL9.8Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command inject...
CVE-2024-34082CRITICAL9.9Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can re...
CVE-2024-28087MEDIUM6.5In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions ...
CVE-2024-28042HIGH8.6SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.
CVE-2024-27593MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allo...
CVE-2024-4903MEDIUM6.3A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code o...
CVE-2024-3319CRITICAL9.1An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints...
CVE-2024-3318MEDIUM4.2A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authent...
CVE-2024-3317MEDIUM6.5An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authen...
CVE-2024-35179MEDIUM6.8Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user...
CVE-2024-31216MEDIUM5.1The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, ...
CVE-2024-34955CRITICAL9.8Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.
CVE-2024-34954MEDIUM6.1Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.
CVE-2024-27353HIGH7.4A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 b...
CVE-2024-25079HIGH7.4A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38...
CVE-2024-25078HIGH7.4A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.2...
CVE-2024-4670HIGH8.8The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu...
CVE-2024-2248MEDIUM6.4A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allo...
CVE-2024-4702MEDIUM5.4The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in al...
CVE-2024-34101MEDIUM5.5Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerabili...
CVE-2024-34100HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-34099HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability ...
CVE-2024-34098HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerabilit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now