2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20655MEDIUM6.6Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability
CVE-2024-20654HIGH8Microsoft ODBC Driver Remote Code Execution Vulnerability
CVE-2024-20653HIGH7.8Microsoft Common Log File System Elevation of Privilege Vulnerability
CVE-2024-20652HIGH8.1Windows HTML Platforms Security Feature Bypass Vulnerability
CVE-2024-0340MEDIUM5.5A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initial...
CVE-2024-0226MEDIUM5.4Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a spec...
CVE-2024-0057CRITICAL9.8NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
CVE-2024-0056HIGH8.7Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
CVE-2024-22165MEDIUM6.5In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perfor...
CVE-2024-22164MEDIUM4.3In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a deni...
CVE-2024-0228——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of ...
CVE-2024-0213HIGH7.8 A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated pe...
CVE-2024-0206HIGH7.8 A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an a...
CVE-2024-22370MEDIUM5.4In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
CVE-2024-22368MEDIUM5.5The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a cra...
CVE-2024-22125HIGH7.5Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allo...
CVE-2024-22124HIGH7.5Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53...
CVE-2024-21738MEDIUM5.4SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in ...
CVE-2024-21737CRITICAL9.1In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to tr...
CVE-2024-21736MEDIUM6.5SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary au...
CVE-2024-21735HIGH7.2SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not per...
CVE-2024-21734MEDIUM5.4SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious pag...
CVE-2024-21646CRITICAL9.8Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP ...
CVE-2024-21663HIGH8.8Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a dis...
CVE-2024-21651MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now