2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24755MEDIUM5.3discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP...
CVE-2024-1040MEDIUM4.4Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by...
CVE-2024-1039CRITICAL9.8Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an ...
CVE-2024-0325HIGH7.8In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.  
CVE-2024-24945MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows att...
CVE-2024-24041MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows att...
CVE-2024-24569MEDIUM4.8The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurre...
CVE-2024-23645MEDIUM6.1GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. U...
CVE-2024-1167HIGH7.5 When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.
CVE-2024-24570MEDIUM6.1Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing f...
CVE-2024-24561CRITICAL9.8Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds...
CVE-2024-24557HIGH7.8Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system i...
CVE-2024-23832CRITICAL9.8Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for aut...
CVE-2024-24754CRITICAL9.8Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a ...
CVE-2024-24753MEDIUM6.5Bref enable serverless PHP on AWS Lambda. When Bref is used in combination with an API Gateway with the v2 format, it do...
CVE-2024-24752MEDIUM6.5Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a ...
CVE-2024-1141MEDIUM5.5A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-s...
CVE-2024-0704Rejected reason: very low impact - impractical to correct
CVE-2024-24062MEDIUM5.4springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.
CVE-2024-24061MEDIUM5.4springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.
CVE-2024-24060MEDIUM5.4springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.
CVE-2024-24059MEDIUM5.4springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded file...
CVE-2024-0935HIGH7.5Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Releas...
CVE-2024-22449HIGH7.8 Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerab...
CVE-2024-22430MEDIUM5.5 Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local l...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now