2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-39302LOW3.7BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be...
CVE-2024-3995LOW2In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.
CVE-2024-38531LOW3.6Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A bui...
CVE-2024-29038LOW3.3tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate ar...
CVE-2024-39157LOW3.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mu...
CVE-2024-39156LOW3.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud...
CVE-2024-39458LOW3.1When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message c...
CVE-2024-6344LOW2.4A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an ...
CVE-2024-28830LOW2.7Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <...
CVE-2024-37141LOW3.5Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerab...
CVE-2024-29177LOW2.7Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary...
CVE-2024-38364LOW2.6DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institut...
CVE-2024-6299LOW3.7Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an...
CVE-2024-6295LOW3.9udn News Android APP stores the unencrypted user session in the local database when user log into the application. A mal...
CVE-2024-6294LOW3.9udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker w...
CVE-2024-4839LOW3.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms...
CVE-2024-3121LOW3.3A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version...
CVE-2024-4841LOW3.3A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode...
CVE-2024-37352LOW3.4There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that...
CVE-2024-37351LOW3.4There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att...
CVE-2024-37349LOW3.4There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att...
CVE-2024-37348LOW3.4There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att...
CVE-2024-37347LOW3.4There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secur...
CVE-2024-37344LOW3.4There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13....
CVE-2024-38358LOW2.9Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now