2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29387HIGH8.8projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/pri...
CVE-2024-29386MEDIUM5.4projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceE...
CVE-2024-27316HIGH7.5HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP...
CVE-2024-24795MEDIUM6.3HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response ...
CVE-2024-22053HIGH8.2A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an...
CVE-2024-22052HIGH7.5A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secur...
CVE-2024-22023MEDIUM5.3An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Se...
CVE-2024-30254MEDIUM5.8MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1...
CVE-2024-30252LOW2.6Livemarks is a browser extension that provides RSS feed bookmark folders. Versions of Livemarks prior to 3.7 are vulnera...
CVE-2024-30249HIGH8.6Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1....
CVE-2024-29193MEDIUM6.1gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. Th...
CVE-2024-25007HIGH7.1 Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application ...
CVE-2024-2660MEDIUM6.8Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP ...
CVE-2024-29192HIGH8.8gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to Cross-Site Request Forgery. The `/...
CVE-2024-28787CRITICAL10IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote at...
CVE-2024-27268HIGH7.5IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sendi...
CVE-2024-25709MEDIUM6.1There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may al...
CVE-2024-25708MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9....
CVE-2024-25706MEDIUM6.1There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticat...
CVE-2024-25705MEDIUM5.4There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below...
CVE-2024-25704Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because this item is schedul...
CVE-2024-25703Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because this item is schedul...
CVE-2024-25700MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 ...
CVE-2024-25699HIGH8.5There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS version...
CVE-2024-25698MEDIUM6.1There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now