2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22455MEDIUM4.6Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key...
CVE-2024-25125MEDIUM5.3Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platfo...
CVE-2024-24699MEDIUM6.5Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network ...
CVE-2024-24698MEDIUM4.4Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via loca...
CVE-2024-24697HIGH7.8Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of pr...
CVE-2024-24696MEDIUM6.5Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind...
CVE-2024-24695MEDIUM6.5Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind...
CVE-2024-24691CRITICAL9.8Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind...
CVE-2024-24690MEDIUM6.5Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via networ...
CVE-2024-1485CRITICAL9.3A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated re...
CVE-2024-25121HIGH7.1TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO...
CVE-2024-25120MEDIUM4.3TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` U...
CVE-2024-25119MEDIUM4.9TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLO...
CVE-2024-25118MEDIUM6.5TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being r...
CVE-2024-24142CRITICAL9.8Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
CVE-2024-25122MEDIUM6.1sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to...
CVE-2024-24814HIGH7.5mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that imp...
CVE-2024-24751HIGH8.8sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected...
CVE-2024-1378CRITICAL9.1A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-1374CRITICAL9.1A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-1372CRITICAL9.1A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-1369CRITICAL9.1A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-1359CRITICAL9.1A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-1355CRITICAL9.1A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...
CVE-2024-1354HIGH8A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now