2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27956CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automat...
CVE-2024-27277MEDIUM5.5The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining...
CVE-2024-27190HIGH8.8Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a thro...
CVE-2024-2465HIGH7.1Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafte...
CVE-2024-2464MEDIUM6.3This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the u...
CVE-2024-2463HIGH8Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX app...
CVE-2024-29244MEDIUM5.3Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3...
CVE-2024-29243CRITICAL9.8Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client...
CVE-2024-27995MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems...
CVE-2024-27994HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooC...
CVE-2024-27993HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista...
CVE-2024-2494MEDIUM6.2A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays bef...
CVE-2024-29880HIGH7.8In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running...
CVE-2024-29879MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/...
CVE-2024-29878MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'descrip...
CVE-2024-29877MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/e...
CVE-2024-29876CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' param...
CVE-2024-29875CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort...
CVE-2024-29874CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_nam...
CVE-2024-29873CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitna...
CVE-2024-29872CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. Th...
CVE-2024-29871CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/i...
CVE-2024-29870CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business...
CVE-2024-29866CRITICAL9.1Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Or...
CVE-2024-28834MEDIUM5.3A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now