2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27476MEDIUM4.7Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.
CVE-2024-27474HIGH8.8Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform...
CVE-2024-24809HIGH8.5Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted u...
CVE-2024-3448MEDIUM5Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?act...
CVE-2024-2731MEDIUM5.4Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages ...
CVE-2024-2730MEDIUM5.3Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated use...
CVE-2024-26816MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86, relocs: Ignore relocations in .notes section ...
CVE-2024-23083MEDIUM5.3Time4J Base v5.9.3 was discovered to contain a NullPointerException via the component net.time4j.format.internal.FormatU...
CVE-2024-31924MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimizer.This issue affec...
CVE-2024-31492HIGH7.8An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0....
CVE-2024-23080CRITICAL9.1Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::...
CVE-2024-20772HIGH7.8Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could...
CVE-2024-20770MEDIUM5.5Photoshop Desktop versions 24.7.2, 25.3.1 and earlier are affected by an out-of-bounds read vulnerability that could lea...
CVE-2024-20766MEDIUM5.5InDesign Desktop versions 18.5.1, 19.2 and earlier are affected by an out-of-bounds read vulnerability that could lead t...
CVE-2024-31309HIGH7.5HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8....
CVE-2024-23076HIGH7.5JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /labels/BubbleXYItemLabelGenerator....
CVE-2024-20759HIGH8.1Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Script...
CVE-2024-20758CRITICAL9Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validati...
CVE-2024-2243HIGH8.8A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can us...
CVE-2024-26815MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: proper TCA_TAPRIO_TC_ENTRY_INDEX...
CVE-2024-26122MEDIUM5.4Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-26098MEDIUM5.4Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-26097MEDIUM5.4Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-26087MEDIUM5.4Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-26084MEDIUM5.4Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now