2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33382 | MEDIUM | 5.3 | 0.5% | May 8, 2024 | An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration |
| CVE-2024-25533 | CRITICAL | 9.4 | 0.7% | May 8, 2024 | Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFil... |
| CVE-2024-25532 | CRITICAL | 9.8 | 0.5% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/ge... |
| CVE-2024-25528 | MEDIUM | 5.9 | 0.3% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai... |
| CVE-2024-31961 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbit... |
| CVE-2024-28971 | MEDIUM | 4.9 | 0.3% | May 8, 2024 | Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log fi... |
| CVE-2024-25531 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit... |
| CVE-2024-25530 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit... |
| CVE-2024-25529 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_o... |
| CVE-2024-25527 | CRITICAL | 9.4 | 0.5% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai... |
| CVE-2024-24908 | MEDIUM | 6.5 | 0.6% | May 8, 2024 | Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A... |
| CVE-2024-24788 | MEDIUM | 5.9 | 1.0% | May 8, 2024 | A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop. |
| CVE-2024-24787 | MEDIUM | 6.4 | 0.8% | May 8, 2024 | On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ... |
| CVE-2024-22460 | HIGH | 7.2 | 0.4% | May 8, 2024 | Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization Vulnerability. A remote attacke... |
| CVE-2024-4654 | CRITICAL | 9.8 | 0.8% | May 8, 2024 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This... |
| CVE-2024-4653 | HIGH | 7.5 | 0.7% | May 8, 2024 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by t... |
| CVE-2024-3951 | HIGH | 7.1 | 0.3% | May 8, 2024 | PTC Codebeamer is vulnerable to a cross site scripting vulnerability that could allow an attacker to inject and execute... |
| CVE-2024-34347 | HIGH | 8.3 | 0.6% | May 8, 2024 | @hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox p... |
| CVE-2024-33612 | MEDIUM | 6.8 | 0.2% | May 8, 2024 | An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impe... |
| CVE-2024-33608 | HIGH | 7.5 | 0.6% | May 8, 2024 | When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to ... |
| CVE-2024-33604 | MEDIUM | 6.1 | 0.3% | May 8, 2024 | A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that... |
| CVE-2024-32980 | CRITICAL | 9.1 | 0.5% | May 8, 2024 | Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some... |
| CVE-2024-32761 | MEDIUM | 6.5 | 0.5% | May 8, 2024 | Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running ... |
| CVE-2024-32113 | CRITICAL | 9.8 | 99.4% | May 8, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue ... |
| CVE-2024-32049 | HIGH | 7.4 | 0.5% | May 8, 2024 | BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instanc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now