2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49797 | MEDIUM | 5.9 | 0.2% | Feb 6, 2025 | IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable... |
| CVE-2024-49796 | MEDIUM | 5.4 | 0.4% | Feb 6, 2025 | IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi... |
| CVE-2024-49795 | MEDIUM | 4.3 | 0.1% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau... |
| CVE-2024-49794 | MEDIUM | 4.3 | 0.1% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau... |
| CVE-2024-49793 | MEDIUM | 5.4 | 0.2% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra... |
| CVE-2024-49792 | MEDIUM | 5.4 | 0.2% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra... |
| CVE-2024-49791 | MEDIUM | 5.4 | 0.2% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra... |
| CVE-2024-56473 | MEDIUM | 5.3 | 0.3% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log f... |
| CVE-2024-56472 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows auth... |
| CVE-2024-56471 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe... |
| CVE-2024-56470 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe... |
| CVE-2024-38318 | MEDIUM | 6.1 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTM... |
| CVE-2024-38317 | MEDIUM | 4.8 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privilege... |
| CVE-2024-38316 | MEDIUM | 6.5 | 0.4% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can sen... |
| CVE-2024-57699 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, conta... |
| CVE-2024-57598 | MEDIUM | 6.5 | 0.4% | Feb 5, 2025 | A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() ... |
| CVE-2024-57520 | CRITICAL | 9.8 | 1.0% | Feb 5, 2025 | Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_cre... |
| CVE-2024-57086 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a De... |
| CVE-2024-57085 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Se... |
| CVE-2024-57084 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to cause a Denial of Service (... |
| CVE-2024-57082 | MEDIUM | 6.5 | 0.3% | Feb 5, 2025 | A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of... |
| CVE-2024-57081 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of S... |
| CVE-2024-57080 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (Do... |
| CVE-2024-57079 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Servic... |
| CVE-2024-57078 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now