2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31967CRITICAL9.1A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-31966MEDIUM6.2A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-31965MEDIUM4.2A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-31964HIGH7.5A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-31963MEDIUM6.4A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-29309HIGH7.7An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Ser...
CVE-2024-4406CRITICAL9.6Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability ...
CVE-2024-4405CRITICAL9.6Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2024-4029MEDIUM4.1A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management...
CVE-2024-3544HIGH7.5 Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to t...
CVE-2024-4128MEDIUM4.3This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint th...
CVE-2024-3543HIGH7.5 Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be ea...
CVE-2024-34148MEDIUM6.8Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 ...
CVE-2024-34147MEDIUM4.3Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file...
CVE-2024-34146MEDIUM6.5Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git re...
CVE-2024-34145HIGH8.8A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jen...
CVE-2024-34144CRITICAL9.8A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_...
CVE-2024-34061MEDIUM4.3changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se...
CVE-2024-33305MEDIUM6.1SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter ...
CVE-2024-33303HIGH8.2SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.
CVE-2024-33302MEDIUM5.3SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add ...
CVE-2024-30251HIGH7.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can sen...
CVE-2024-23462HIGH7.5An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of se...
CVE-2024-23461MEDIUM5.5An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade pr...
CVE-2024-23459CRITICAL9.8An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allow...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now