2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24023CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ...
CVE-2024-24018CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset...
CVE-2024-24806HIGH7.3libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/g...
CVE-2024-23448HIGH7.5An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that index...
CVE-2024-1066MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and ...
CVE-2024-24488MEDIUM5.5An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive informatio...
CVE-2024-22984Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2024-23769MEDIUM5.5Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacke...
CVE-2024-24824HIGH8.8Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, ar...
CVE-2024-24823MEDIUM4.4Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, re...
CVE-2024-24822CRITICAL9.1Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can cr...
CVE-2024-24816MEDIUM6.1CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability...
CVE-2024-24706MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Forum One WP-CFM wp-cfm.This issue affects WP-CFM: from n/a through 1...
CVE-2024-24563CRITICAL9.8Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, w...
CVE-2024-23806MEDIUM5.3Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device ...
CVE-2024-20290HIGH7.5A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a deni...
CVE-2024-20255HIGH7.1A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow...
CVE-2024-20254HIGH8.8Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow ...
CVE-2024-20252HIGH8.8Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow ...
CVE-2024-24815MEDIUM6.1CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been disc...
CVE-2024-22012HIGH7.8there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege ...
CVE-2024-25145MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 ...
CVE-2024-25143MEDIUM6.5The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3...
CVE-2024-24812MEDIUM5.4Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrate...
CVE-2024-24811CRITICAL9.8SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unaut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now