2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3684HIGH7.2A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an ...
CVE-2024-3646HIGH7.2A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-3470HIGH7.2An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us...
CVE-2024-32644CRITICAL9.1Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ether...
CVE-2024-32478MEDIUM6.9Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root own...
CVE-2024-32038CRITICAL9.8Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow...
CVE-2024-29030MEDIUM5.3memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/res...
CVE-2024-29028MEDIUM5.3memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/h...
CVE-2024-32166HIGH8.8Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing att...
CVE-2024-3654MEDIUM6.3An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an ...
CVE-2024-31745Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-2002. Reason: This candidate is a duplicate of C...
CVE-2024-31744HIGH7.5In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnera...
CVE-2024-32683HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimat...
CVE-2024-1065MEDIUM5.9Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2024-0671MEDIUM6.8Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GP...
CVE-2024-29969HIGH7.5When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message ...
CVE-2024-29968MEDIUM6.5An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances...
CVE-2024-2761MEDIUM6.8The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, all...
CVE-2024-29967MEDIUM6In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance ha...
CVE-2024-29966CRITICAL9.8Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appl...
CVE-2024-29965MEDIUM5.9 In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the com...
CVE-2024-29964MEDIUM6.5Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivilege...
CVE-2024-29962MEDIUM5.5Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. T...
CVE-2024-29963LOW3.8 Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't ...
CVE-2024-29961HIGH8.2A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping comman...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now