2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3485 | HIGH | 7.5 | 0.3% | May 15, 2024 | Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senst... |
| CVE-2024-3484 | CRITICAL | 9.8 | 0.5% | May 15, 2024 | Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure. |
| CVE-2024-3483 | CRITICAL | 9.8 | 1.0% | May 15, 2024 | Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command inject... |
| CVE-2024-34082 | CRITICAL | 9.9 | 3.1% | May 15, 2024 | Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can re... |
| CVE-2024-28087 | MEDIUM | 6.5 | 0.3% | May 15, 2024 | In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions ... |
| CVE-2024-28042 | HIGH | 8.6 | 0.2% | May 15, 2024 | SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center. |
| CVE-2024-27593 | MEDIUM | 5.4 | 0.3% | May 15, 2024 | A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allo... |
| CVE-2024-4903 | MEDIUM | 6.3 | 0.4% | May 15, 2024 | A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code o... |
| CVE-2024-3319 | CRITICAL | 9.1 | 0.8% | May 15, 2024 | An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints... |
| CVE-2024-3318 | MEDIUM | 4.2 | 0.4% | May 15, 2024 | A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authent... |
| CVE-2024-3317 | MEDIUM | 6.5 | 0.4% | May 15, 2024 | An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authen... |
| CVE-2024-35179 | MEDIUM | 6.8 | 0.6% | May 15, 2024 | Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user... |
| CVE-2024-31216 | MEDIUM | 5.1 | 0.2% | May 15, 2024 | The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, ... |
| CVE-2024-34955 | CRITICAL | 9.8 | 0.6% | May 15, 2024 | Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter. |
| CVE-2024-34954 | MEDIUM | 6.1 | 0.3% | May 15, 2024 | Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter. |
| CVE-2024-27353 | HIGH | 7.4 | 0.2% | May 15, 2024 | A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 b... |
| CVE-2024-25079 | HIGH | 7.4 | 0.1% | May 15, 2024 | A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38... |
| CVE-2024-25078 | HIGH | 7.4 | 0.1% | May 15, 2024 | A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.2... |
| CVE-2024-4670 | HIGH | 8.8 | 0.6% | May 15, 2024 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu... |
| CVE-2024-2248 | MEDIUM | 6.4 | 0.3% | May 15, 2024 | A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allo... |
| CVE-2024-4702 | MEDIUM | 5.4 | 0.3% | May 15, 2024 | The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in al... |
| CVE-2024-34101 | MEDIUM | 5.5 | 0.5% | May 15, 2024 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerabili... |
| CVE-2024-34100 | HIGH | 7.8 | 0.4% | May 15, 2024 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could... |
| CVE-2024-34099 | HIGH | 7.8 | 0.4% | May 15, 2024 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability ... |
| CVE-2024-34098 | HIGH | 7.8 | 0.4% | May 15, 2024 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerabilit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now