2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-34328MEDIUM6.3An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.
CVE-2024-45515MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in...
CVE-2024-43018MEDIUM6.4Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters ar...
CVE-2024-52894MEDIUM4.9IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-49343MEDIUM5.4IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HT...
CVE-2024-58265MEDIUM4.3The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby deny...
CVE-2024-58263MEDIUM5.3The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.
CVE-2024-58262MEDIUM5.1The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed...
CVE-2024-48730MEDIUM6.5The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions...
CVE-2024-41751MEDIUM5.5IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au...
CVE-2024-41750MEDIUM5.5IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, au...
CVE-2024-40686MEDIUM6.1IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP h...
CVE-2024-40682MEDIUM5.5IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local use...
CVE-2024-53288MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functio...
CVE-2024-53287MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functi...
CVE-2024-38335MEDIUM4.5IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of serv...
CVE-2024-55040MEDIUM6.1Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker ...
CVE-2024-13175MEDIUM5.5Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. T...
CVE-2024-32124MEDIUM4.3An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions loggi...
CVE-2024-27779MEDIUM6.7An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version...
CVE-2024-42912MEDIUM5.4A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attac...
CVE-2024-9343MEDIUM6.1In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con...
CVE-2024-10032MEDIUM5.4In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Con...
CVE-2024-10031MEDIUM5.4In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configur...
CVE-2024-10029MEDIUM6.1In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now