2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-58370MEDIUM6.5SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin...
CVE-2024-58367MEDIUM6.5SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations,...
CVE-2024-58363MEDIUM6.3SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clau...
CVE-2024-58358MEDIUM6.9SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owne...
CVE-2024-58356MEDIUM6.3SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used ...
CVE-2024-42214MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method ...
CVE-2024-23578MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) ...
CVE-2024-23577MEDIUM4.3HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary...
CVE-2024-23575MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information ...
CVE-2024-23574MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to ...
CVE-2024-23572MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as...
CVE-2024-23571MEDIUM4.3HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying...
CVE-2024-23570MEDIUM4.3HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta...
CVE-2024-23569MEDIUM4.3HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23568MEDIUM5.3HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th...
CVE-2024-23567MEDIUM4.3HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti...
CVE-2024-23566MEDIUM6.5HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead...
CVE-2024-23565MEDIUM5.3HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism ...
CVE-2024-32387MEDIUM5.7An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv...
CVE-2024-32385MEDIUM4.3An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv...
CVE-2024-58360MEDIUM6.9stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verifica...
CVE-2024-56141MEDIUM5Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b0...
CVE-2024-1248MEDIUM5.3The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segrega...
CVE-2024-51454MEDIUM6.1IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 th...
CVE-2024-54178MEDIUM6.5IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authen...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now