2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-24454MEDIUM5.9An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11....
CVE-2024-24453MEDIUM5.9An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element ...
CVE-2024-24452MEDIUM5.9An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME ...
CVE-2024-11259MEDIUM6.1A vulnerability, which was classified as problematic, has been found in code-projects Farmacia 1.0. This issue affects s...
CVE-2024-51330MEDIUM5.1An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-proce...
CVE-2024-51142MEDIUM5.4Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey p...
CVE-2024-51037MEDIUM5.3An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature...
CVE-2024-43418MEDIUM6.1GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI ...
CVE-2024-43417MEDIUM6.1GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI ...
CVE-2024-24446MEDIUM6.5An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Ser...
CVE-2024-24425MEDIUM6.5Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req f...
CVE-2024-23169MEDIUM4.6The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports scre...
CVE-2024-52522MEDIUM5.4Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure h...
CVE-2024-52513MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share li...
CVE-2024-52512MEDIUM6.1user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that w...
CVE-2024-52511MEDIUM6.5Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or v...
CVE-2024-52509MEDIUM5.7Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly al...
CVE-2024-52507MEDIUM4.3Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is s...
CVE-2024-50800MEDIUM5.4Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary...
CVE-2024-47759MEDIUM4.8GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. T...
CVE-2024-41678MEDIUM6.1GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI ...
CVE-2024-24450MEDIUM5.3Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN...
CVE-2024-24449MEDIUM6.5An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows at...
CVE-2024-24447MEDIUM5.3A buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function of oai-cn5g-amf up to v2.0.0 allow...
CVE-2024-52523MEDIUM6.5Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external stora...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now