2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25602MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7...
CVE-2024-25601MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 th...
CVE-2024-25152MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older...
CVE-2024-25147MEDIUM6.1Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsup...
CVE-2024-24475Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-0407MEDIUM6.5Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, w...
CVE-2024-23758HIGH7.5An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise Manage...
CVE-2024-26140MEDIUM6.1com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5...
CVE-2024-26136HIGH7.5kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an accou...
CVE-2024-25428MEDIUM6.5SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.
CVE-2024-23830HIGH8.3MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email ...
CVE-2024-25141CRITICAL9.1When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not ...
CVE-2024-26135HIGH8.8MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vu...
CVE-2024-25631MEDIUM5.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have ena...
CVE-2024-25630MEDIUM5.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are usin...
CVE-2024-25260MEDIUM4elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
CVE-2024-24763MEDIUM6.1JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10....
CVE-2024-24474HIGH8.8QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA tra...
CVE-2024-22250HIGH7.8Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unp...
CVE-2024-22245CRITICAL9.6Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-...
CVE-2024-22054HIGH7.5A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functi...
CVE-2024-21682HIGH7.2This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Disco...
CVE-2024-21678HIGH8.5This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XS...
CVE-2024-0794CRITICAL9.8Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote C...
CVE-2024-25366MEDIUM6.2Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of serv...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now