2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56335HIGH7.5vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve...
CVE-2024-56334HIGH7.8systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when ...
CVE-2024-55509CRITICAL9.8SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary...
CVE-2024-40875MEDIUM5.9There is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.52...
CVE-2024-12844MEDIUM6.1A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of th...
CVE-2024-12843MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown pr...
CVE-2024-56333CRITICAL9.4Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of ...
CVE-2024-56331MEDIUM6.8Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacke...
CVE-2024-56330CRITICAL9.3Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC)...
CVE-2024-56329HIGH8.9Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffo...
CVE-2024-55341MEDIUM4.7A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaS...
CVE-2024-12867HIGH8.8Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthent...
CVE-2024-12842MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unkn...
CVE-2024-55342MEDIUM4.7A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /m...
CVE-2024-37758HIGH8.8Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attacker...
CVE-2024-12841MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part ...
CVE-2024-12677HIGH8.5Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.
CVE-2024-56337CRITICAL9.8Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: fro...
CVE-2024-55471MEDIUM6.5Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This all...
CVE-2024-55470HIGH7.5Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can ...
CVE-2024-55186MEDIUM4.3An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to ...
CVE-2024-12840——Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described ...
CVE-2024-10385HIGH8.6Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-p...
CVE-2024-56356HIGH7.1In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
CVE-2024-56355MEDIUM5.4In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now