2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29150HIGH8.8An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu...
CVE-2024-29149HIGH7.4An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu...
CVE-2024-27982MEDIUM6.5The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed ...
CVE-2024-4596MEDIUM6.5A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown fu...
CVE-2024-34341MEDIUM5.4Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when cop...
CVE-2024-33858MEDIUM5.3An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment s...
CVE-2024-33857CRITICAL9.6An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an a...
CVE-2024-33856MEDIUM5.3An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the r...
CVE-2024-33748MEDIUM4.1Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.
CVE-2024-33146CRITICAL9.1J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export funct...
CVE-2024-33144HIGH8.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedT...
CVE-2024-33139HIGH7.5J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage fun...
CVE-2024-4595MEDIUM6.5A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the fun...
CVE-2024-4594MEDIUM4.3A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. Affected is an unknown function of the f...
CVE-2024-34523HIGH7.5AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by usin...
CVE-2024-34342HIGH7.1react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalS...
CVE-2024-34084HIGH7.5Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerab...
CVE-2024-33124CRITICAL9.8Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() fun...
CVE-2024-33122MEDIUM6.3Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
CVE-2024-33120CRITICAL9.8Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload...
CVE-2024-32867MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-32664HIGH7.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-32663HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-32371HIGH7.5An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their p...
CVE-2024-32370CRITICAL9.8An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive info...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now