2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23204HIGH7.5The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17....
CVE-2024-23203HIGH7.5The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17....
CVE-2024-23345MEDIUM5.4Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot...
CVE-2024-23342HIGH7.4The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El...
CVE-2024-23340MEDIUM5.3@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server h...
CVE-2024-23339MEDIUM6.5hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0...
CVE-2024-23678HIGH8.8In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path inpu...
CVE-2024-23677MEDIUM5.3In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applica...
CVE-2024-23676LOW3.5In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index ...
CVE-2024-23675MEDIUM6.5In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permission...
CVE-2024-0606MEDIUM6.1An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascr...
CVE-2024-0605HIGH7.5Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sit...
CVE-2024-0430MEDIUM5.5IObit Malware Fighter v11.0.0.1274 is vulnerable to a Denial of Service vulnerability by triggering the 0x8001E00C IOCTL...
CVE-2024-0784CRITICAL9.8A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function ...
CVE-2024-0783CRITICAL9.8A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects s...
CVE-2024-0204CRITICAL9.8Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via ...
CVE-2024-0782MEDIUM6.1A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vu...
CVE-2024-0781MEDIUM6.1A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects a...
CVE-2024-0778CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S ...
CVE-2024-22895HIGH8.8DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.
CVE-2024-0706Rejected reason: ***REJECT*** This was a false positive report.
CVE-2024-22233HIGH7.5In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that...
CVE-2024-0775HIGH7.1A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a...
CVE-2024-22113MEDIUM6.1Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote ...
CVE-2024-21484MEDIUM5.9Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now