2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32236LOW3.5An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in...
CVE-2024-31574MEDIUM5Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script
CVE-2024-30890MEDIUM4.7Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categori...
CVE-2024-2467MEDIUM5.9A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plai...
CVE-2024-29660MEDIUM5.3Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payl...
CVE-2024-28241HIGH7.8The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DL...
CVE-2024-28240HIGH7.8The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI ...
CVE-2024-25624MEDIUM6.8Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations....
CVE-2024-1726MEDIUM5.3A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoin...
CVE-2024-1657HIGH8.1A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation fro...
CVE-2024-1139HIGH7.7A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote att...
CVE-2024-1102MEDIUM6.5A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as ...
CVE-2024-0874MEDIUM5.3A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented cac...
CVE-2024-33592MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a throu...
CVE-2024-25569MEDIUM6.5An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DIC...
CVE-2024-22391CRITICAL9.8A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroo...
CVE-2024-22373CRITICAL9.8An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malater...
CVE-2024-4172MEDIUM4.3A vulnerability classified as problematic was found in idcCMS 1.35. Affected by this vulnerability is an unknown functio...
CVE-2024-4171HIGH8.8A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHan...
CVE-2024-4024HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starti...
CVE-2024-4006MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions start...
CVE-2024-4170HIGH8.8A vulnerability was found in Tenda 4G300 1.01.42. It has been rated as critical. This issue affects the function sub_429...
CVE-2024-4169HIGH8.8A vulnerability was found in Tenda 4G300 1.01.42. It has been declared as critical. This vulnerability affects the funct...
CVE-2024-33247HIGH8.8Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php.
CVE-2024-25026HIGH7.5IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vul...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now