2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53964 | MEDIUM | 5.4 | 0.4% | Feb 5, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-53963 | MEDIUM | 5.4 | 0.4% | Feb 5, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-53962 | MEDIUM | 5.4 | 0.4% | Feb 5, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-48445 | CRITICAL | 9.8 | 1.8% | Feb 4, 2025 | An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t... |
| CVE-2024-11468 | HIGH | 7.8 | 0.2% | Feb 4, 2025 | Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installa... |
| CVE-2024-11467 | HIGH | 7.8 | 0.2% | Feb 4, 2025 | Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successf... |
| CVE-2024-8125 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Param... |
| CVE-2024-53994 | MEDIUM | 4.3 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions users who disable chat in preference... |
| CVE-2024-53851 | MEDIUM | 6.5 | 0.4% | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline o... |
| CVE-2024-53266 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, a... |
| CVE-2024-13723 | HIGH | 7.2 | 1.2% | Feb 4, 2025 | The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrat... |
| CVE-2024-13722 | MEDIUM | 5.4 | 0.5% | Feb 4, 2025 | The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious... |
| CVE-2024-56328 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' br... |
| CVE-2024-56197 | MEDIUM | 4.9 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when th... |
| CVE-2024-55948 | HIGH | 8.2 | 0.2% | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR re... |
| CVE-2024-45658 | MEDIUM | 5.3 | 0.4% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti... |
| CVE-2024-45657 | MEDIUM | 6.7 | 0.1% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform ... |
| CVE-2024-43187 | HIGH | 7.5 | 0.2% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data i... |
| CVE-2024-40700 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vul... |
| CVE-2024-35138 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery whi... |
| CVE-2024-48019 | MEDIUM | 5.4 | 0.9% | Feb 4, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to Exter... |
| CVE-2024-45659 | MEDIUM | 5.3 | 0.3% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti... |
| CVE-2024-9644 | CRITICAL | 9.8 | 0.6% | Feb 4, 2025 | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the admini... |
| CVE-2024-9643 | CRITICAL | 9.8 | 3.0% | Feb 4, 2025 | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials i... |
| CVE-2024-23690 | HIGH | 7.2 | 1.2% | Feb 4, 2025 | The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now