2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-30924MEDIUM4.6Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin...
CVE-2024-22179HIGH8.7The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentia...
CVE-2024-30923CRITICAL9.8SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where ...
CVE-2024-30922CRITICAL9.8SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in ...
CVE-2024-30921MEDIUM5.4Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the...
CVE-2024-30920HIGH7.4Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the...
CVE-2024-30107MEDIUM6.5HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized use...
CVE-2024-32477HIGH7.4Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a rac...
CVE-2024-32474MEDIUM6.5Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to ...
CVE-2024-20380HIGH7.5A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of servic...
CVE-2024-29987MEDIUM6.5Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-29986MEDIUM5.4Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
CVE-2024-23557MEDIUM4.3HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the u...
CVE-2024-32462HIGH8.4Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before ...
CVE-2024-24910HIGH7.3A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for ...
CVE-2024-32335MEDIUM5.4TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under ...
CVE-2024-32334MEDIUM6.5TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering und...
CVE-2024-32333MEDIUM4.3TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under t...
CVE-2024-32332MEDIUM6.1TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under th...
CVE-2024-32327MEDIUM5.5TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under...
CVE-2024-32326MEDIUM6.8TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in t...
CVE-2024-32325LOW2.4TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in ...
CVE-2024-32475HIGH7.5Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enable...
CVE-2024-32470MEDIUM6.5Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission ch...
CVE-2024-32466MEDIUM4.3Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/transl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now