2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49797MEDIUM5.9IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable...
CVE-2024-49796MEDIUM5.4IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi...
CVE-2024-49795MEDIUM4.3IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2024-49794MEDIUM4.3IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2024-49793MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-49792MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-49791MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-56473MEDIUM5.3IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log f...
CVE-2024-56472MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows auth...
CVE-2024-56471MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe...
CVE-2024-56470MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe...
CVE-2024-38318MEDIUM6.1IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTM...
CVE-2024-38317MEDIUM4.8IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privilege...
CVE-2024-38316MEDIUM6.5IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can sen...
CVE-2024-57699HIGH7.5A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, conta...
CVE-2024-57598MEDIUM6.5A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() ...
CVE-2024-57520CRITICAL9.8Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_cre...
CVE-2024-57086HIGH7.5A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a De...
CVE-2024-57085HIGH7.5A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Se...
CVE-2024-57084HIGH7.5A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to cause a Denial of Service (...
CVE-2024-57082MEDIUM6.5A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of...
CVE-2024-57081HIGH7.5A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of S...
CVE-2024-57080HIGH7.5A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (Do...
CVE-2024-57079HIGH7.5A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Servic...
CVE-2024-57078HIGH7.5A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now