2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-52056MEDIUM6.5Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any...
CVE-2024-52055MEDIUM4.9Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any f...
CVE-2024-52616MEDIUM5.3A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementi...
CVE-2024-52615MEDIUM5.3A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies at...
CVE-2024-49588MEDIUM6.8Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.
CVE-2024-53094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SP...
CVE-2024-53093MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need t...
CVE-2024-53092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct i...
CVE-2024-53091MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has...
CVE-2024-53090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() c...
CVE-2024-53089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard inte...
CVE-2024-53333MEDIUM6.3TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. Th...
CVE-2024-52309MEDIUM5.1SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur...
CVE-2024-52307MEDIUM5.6authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ en...
CVE-2024-49529MEDIUM5.5InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2024-45517MEDIUM5.4An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h...
CVE-2024-45513MEDIUM4.8An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability ex...
CVE-2024-45194MEDIUM4.8In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Si...
CVE-2024-8526MEDIUM5.9A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when vis...
CVE-2024-45514MEDIUM5.4An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists i...
CVE-2024-45512MEDIUM5.4An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerabilit...
CVE-2024-48747MEDIUM6.8An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.
CVE-2024-7130MEDIUM5.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Comput...
CVE-2024-53426MEDIUM6.2A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
CVE-2024-53425MEDIUM6.2A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue oc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now