2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25940MEDIUM6.3`bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected v...
CVE-2024-25559MEDIUM4.7URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request...
CVE-2024-1488HIGH7.3A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound grou...
CVE-2024-26264CRITICAL9.8EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page...
CVE-2024-26263HIGH7.5EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse speci...
CVE-2024-26262HIGH8.8EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remot...
CVE-2024-26261CRITICAL9.8The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulner...
CVE-2024-26260CRITICAL9.8The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, all...
CVE-2024-1523HIGH8.8EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authent...
CVE-2024-25620MEDIUM6.4Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm cli...
CVE-2024-24301HIGH8.8Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allo...
CVE-2024-24300CRITICAL9.84ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardle...
CVE-2024-1471MEDIUM4.8 An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Sec...
CVE-2024-1367HIGH7.2 A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the S...
CVE-2024-25619MEDIUM4.3Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the ...
CVE-2024-25618HIGH7.4Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configur...
CVE-2024-25617HIGH7.5Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into ...
CVE-2024-25165HIGH7.8A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.
CVE-2024-1482MEDIUM6.5An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create n...
CVE-2024-25301HIGH7.2Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates....
CVE-2024-25300MEDIUM4.8A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-0011MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software...
CVE-2024-0010MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS so...
CVE-2024-0009MEDIUM6.3An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enable...
CVE-2024-0008HIGH8.8Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, maki...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now