2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22877MEDIUM5.4StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This ...
CVE-2024-22876MEDIUM5.4StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment ...
CVE-2024-0713——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-28871. Reason: This candidate is a ...
CVE-2024-0712CRITICAL9.8A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affect...
CVE-2024-21733MEDIUM5.3Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache To...
CVE-2024-0705HIGH7.5The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in ...
CVE-2024-23659MEDIUM6.1SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/big...
CVE-2024-23387MEDIUM4.8FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote a...
CVE-2024-22424HIGH8.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2....
CVE-2024-22422HIGH7.5AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use a...
CVE-2024-0696MEDIUM6.1A vulnerability, which was classified as problematic, was found in AtroCore AtroPIM 1.8.4. This affects an unknown part ...
CVE-2024-0695MEDIUM5.3A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue...
CVE-2024-0693HIGH7.5A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is ...
CVE-2024-22418MEDIUM5.4Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present ...
CVE-2024-22415CRITICAL9.8jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion +...
CVE-2024-22404MEDIUM4.3Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected v...
CVE-2024-22402MEDIUM5.4Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions ...
CVE-2024-22401MEDIUM4.3Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions ...
CVE-2024-22403LOW3.7Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attack...
CVE-2024-22400MEDIUM6.1Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a l...
CVE-2024-22213MEDIUM5.4Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with N...
CVE-2024-22419CRITICAL9.8Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the b...
CVE-2024-22212CRITICAL9.8Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users t...
CVE-2024-0694——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6620. Reason: This candidate is a r...
CVE-2024-22819HIGH8.8FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now