2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1013HIGH7.8An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee ...
CVE-2024-1606MEDIUM5.4Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of gener...
CVE-2024-1605HIGH7.8BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that g...
CVE-2024-1604MEDIUM6.8Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows l...
CVE-2024-28039MEDIUM5.8Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a rem...
CVE-2024-28128MEDIUM6.1Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticat...
CVE-2024-28125CRITICAL9.8FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of Fi...
CVE-2024-27974MEDIUM6.3Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet S...
CVE-2024-23604MEDIUM6.1Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to...
CVE-2024-22475MEDIUM6.1Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided...
CVE-2024-21824MEDIUM5.3Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management p...
CVE-2024-29156MEDIUM6.5In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL ...
CVE-2024-29154HIGH7.4danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling,...
CVE-2024-29151CRITICAL9.1Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.
CVE-2024-28745LOW3.3Improper export of Android application components issue exists in 'ABEMA' App for Android prior to 10.65.0 allowing anot...
CVE-2024-27757MEDIUM6.1flusity CMS through 2.45 allows tools/addons_model.php Gallery Name XSS. The reporter indicates that this product "cease...
CVE-2024-2581HIGH8.8A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function fromSetR...
CVE-2024-2577CRITICAL9.8A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vu...
CVE-2024-24539MEDIUM5.3FusionPBX before 5.2.0 does not validate a session.
CVE-2024-2576CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This...
CVE-2024-2575CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0....
CVE-2024-2574CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this...
CVE-2024-24230HIGH7.5Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It al...
CVE-2024-2573CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is...
CVE-2024-2572CRITICAL9.8A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This iss...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now