2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23298MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekee...
CVE-2024-28848HIGH8.8OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository...
CVE-2024-28847HIGH8.8OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository...
CVE-2024-28255CRITICAL9.8OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository...
CVE-2024-28254HIGH8.8OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository...
CVE-2024-28253HIGH8.8OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository...
CVE-2024-28242HIGH7.5Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret ca...
CVE-2024-27920HIGH7.4projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant s...
CVE-2024-27351MEDIUM5.3In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (wi...
CVE-2024-27100MEDIUM6.5Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, ...
CVE-2024-27085MEDIUM6.5Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite oth...
CVE-2024-24827HIGH7.5Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it ma...
CVE-2024-24748MEDIUM5.3Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret ...
CVE-2024-28854HIGH7.5tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-l...
CVE-2024-28851HIGH7.8The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive Met...
CVE-2024-28252HIGH7.5CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. If you have a NetFraming b...
CVE-2024-2537CRITICAL9.8Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code In...
CVE-2024-2193MEDIUM5.7A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution ...
CVE-2024-2497HIGH7.2A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown proc...
CVE-2024-28404HIGH8TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering...
CVE-2024-28401MEDIUM5.4TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Co...
CVE-2024-28403MEDIUM5.4TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.
CVE-2024-28319MEDIUM6.2gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_...
CVE-2024-28318HIGH7.1gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string...
CVE-2024-25597MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now