2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26133MEDIUM4.9EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the project...
CVE-2024-26130HIGH7.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in vers...
CVE-2024-25288MEDIUM4.9SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
CVE-2024-25117CRITICAL9.8php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fail...
CVE-2024-24478HIGH7.5An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_b...
CVE-2024-23346HIGH7.8Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulner...
CVE-2024-20325HIGH7.1A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attac...
CVE-2024-1714HIGH7.1An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value...
CVE-2024-1703MEDIUM5.3A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function...
CVE-2024-1702CRITICAL9.8A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this iss...
CVE-2024-27215Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1709. Reason: This candidate is a duplicate of C...
CVE-2024-22220MEDIUM6.3An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL...
CVE-2024-1709CRITICAL10ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel ...
CVE-2024-1708HIGH8.4ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker t...
CVE-2024-1701CRITICAL9.8A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by thi...
CVE-2024-1700MEDIUM5.4A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected ...
CVE-2024-1474MEDIUM6.1In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user suppl...
CVE-2024-26585MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket...
CVE-2024-26584MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Si...
CVE-2024-26583MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close...
CVE-2024-26582HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and...
CVE-2024-22778HIGH7.5HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.
CVE-2024-24837MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drup...
CVE-2024-24802HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in John Tendik JTRT Responsive Tables.This issue affects JTRT Responsive...
CVE-2024-24798HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SoniNow Team Debug.This issue affects Debug: from n/a through 1.10.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now