2024 CVE Vulnerabilities

39,152 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-52286LOW2Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In affected...
CVE-2024-43427LOW3.7A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are ...
CVE-2024-47190LOW2.7Northern.tech Hosted Mender before 2024.07.11 allows SSRF.
CVE-2024-50211LOW3.3In the Linux kernel, the following vulnerability has been resolved: udf: refactor inode_bmap() to handle error Refacto...
CVE-2024-51993LOW3.4Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read som...
CVE-2024-51758LOW2.3Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that intera...
CVE-2024-30142LOW3.8HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be sto...
CVE-2024-50343LOW3.1symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to ...
CVE-2024-50341LOW3.1symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security co...
CVE-2024-51755LOW2.2Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were ...
CVE-2024-51754LOW2.2Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toStr...
CVE-2024-10920LOW2.3A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this ...
CVE-2024-34682LOW2.4Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi passw...
CVE-2024-34677LOW3.3Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious a...
CVE-2024-51756LOW2.3The cap-std project is organized around the eponymous `cap-std` crate, and develops libraries to make it easy to write c...
CVE-2024-51745LOW2.3Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks ac...
CVE-2024-51753LOW2.1The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthK...
CVE-2024-51752LOW2.1The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut...
CVE-2024-51746LOW1.8Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the...
CVE-2024-50092LOW3.3In the Linux kernel, the following vulnerability has been resolved: net: netconsole: fix wrong warning A warning is tr...
CVE-2024-51744LOW3.1golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` c...
CVE-2024-10749LOW2.3A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script...
CVE-2024-10748LOW2A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. ...
CVE-2024-39639LOW3.5Broken Access Control vulnerability in Nickolas Bossinas WordPress File Upload allows Exploiting Incorrectly Configured ...
CVE-2024-7883LOW3.7When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floatin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now