2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29150 | HIGH | 8.8 | 0.5% | May 7, 2024 | An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu... |
| CVE-2024-29149 | HIGH | 7.4 | 0.2% | May 7, 2024 | An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones throu... |
| CVE-2024-27982 | MEDIUM | 6.5 | 1.2% | May 7, 2024 | The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed ... |
| CVE-2024-4596 | MEDIUM | 6.5 | 0.8% | May 7, 2024 | A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown fu... |
| CVE-2024-34341 | MEDIUM | 5.4 | 0.8% | May 7, 2024 | Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when cop... |
| CVE-2024-33858 | MEDIUM | 5.3 | 0.5% | May 7, 2024 | An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment s... |
| CVE-2024-33857 | CRITICAL | 9.6 | 0.4% | May 7, 2024 | An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an a... |
| CVE-2024-33856 | MEDIUM | 5.3 | 0.4% | May 7, 2024 | An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the r... |
| CVE-2024-33748 | MEDIUM | 4.1 | 0.4% | May 7, 2024 | Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier. |
| CVE-2024-33146 | CRITICAL | 9.1 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export funct... |
| CVE-2024-33144 | HIGH | 8.8 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedT... |
| CVE-2024-33139 | HIGH | 7.5 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage fun... |
| CVE-2024-4595 | MEDIUM | 6.5 | 0.6% | May 7, 2024 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the fun... |
| CVE-2024-4594 | MEDIUM | 4.3 | 0.4% | May 7, 2024 | A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. Affected is an unknown function of the f... |
| CVE-2024-34523 | HIGH | 7.5 | 0.8% | May 7, 2024 | AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by usin... |
| CVE-2024-34342 | HIGH | 7.1 | 1.1% | May 7, 2024 | react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalS... |
| CVE-2024-34084 | HIGH | 7.5 | 0.6% | May 7, 2024 | Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerab... |
| CVE-2024-33124 | CRITICAL | 9.8 | 0.5% | May 7, 2024 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() fun... |
| CVE-2024-33122 | MEDIUM | 6.3 | 0.3% | May 7, 2024 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function. |
| CVE-2024-33120 | CRITICAL | 9.8 | 0.8% | May 7, 2024 | Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload... |
| CVE-2024-32867 | MEDIUM | 5.3 | 0.7% | May 7, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-32664 | HIGH | 7.3 | 0.9% | May 7, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-32663 | HIGH | 7.5 | 1.0% | May 7, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-32371 | HIGH | 7.5 | 0.7% | May 7, 2024 | An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their p... |
| CVE-2024-32370 | CRITICAL | 9.8 | 1.0% | May 7, 2024 | An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive info... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now