2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7952HIGH8.7A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to ...
CVE-2024-14047HIGH7.1A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by u...
CVE-2024-10085HIGH8.2CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of...
CVE-2024-58379MEDIUM5.3nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUr...
CVE-2024-58378——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2024-58377——Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2024-13942HIGH7.6Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me...
CVE-2024-58376MEDIUM6.7Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAli...
CVE-2024-14046MEDIUM6.3A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController ...
CVE-2024-14045MEDIUM6.3A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/...
CVE-2024-58375HIGH7.5OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into...
CVE-2024-13784CRITICAL9.8The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection...
CVE-2024-58374HIGH7.5Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows r...
CVE-2024-27253CRITICAL10IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform...
CVE-2024-14044MEDIUM6.3A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc...
CVE-2024-14043MEDIUM6.3A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data...
CVE-2024-14042MEDIUM6.3A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr...
CVE-2024-6541MEDIUM6.8The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy...
CVE-2024-39024HIGH8.8In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
CVE-2024-8995MEDIUM4.9Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a...
CVE-2024-6832HIGH7.5The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta...
CVE-2024-10302MEDIUM5.8The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo...
CVE-2024-40683MEDIUM6.3IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,...
CVE-2024-25039HIGH7.5IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1...
CVE-2024-14041MEDIUM5.9In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now