2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23756HIGH7.5The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated...
CVE-2024-24115MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated ...
CVE-2024-23660HIGH7.5The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezo...
CVE-2024-22836CRITICAL9.8An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc...
CVE-2024-1329HIGH7.5HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file wri...
CVE-2024-0242CRITICAL9.8Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access ...
CVE-2024-24215MEDIUM5.3An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configu...
CVE-2024-23764MEDIUM6.7Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, With...
CVE-2024-22795HIGH7Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privi...
CVE-2024-24321CRITICAL9.8An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 pa...
CVE-2024-24213CRITICAL9.8Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/que...
CVE-2024-25191CRITICAL9.8php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...
CVE-2024-25190CRITICAL9.8l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...
CVE-2024-25189CRITICAL9.8libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...
CVE-2024-24834MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – ...
CVE-2024-24878MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Almeida | We...
CVE-2024-24877MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Lt...
CVE-2024-24871MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq B...
CVE-2024-24836MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Audrasjb GDPR Data...
CVE-2024-24113HIGH8.8xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control ex...
CVE-2024-1312MEDIUM4.7A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same...
CVE-2024-1150MEDIUM5.5Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Mani...
CVE-2024-1149MEDIUM5.5Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software ...
CVE-2024-0985HIGH8Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrar...
CVE-2024-24885MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lê Văn Toản Woocom...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now