2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-48793MEDIUM5.9An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware ...
CVE-2024-48790MEDIUM5.3An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware ...
CVE-2024-47826MEDIUM6.1eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows a...
CVE-2024-47767MEDIUM4.3Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-47766MEDIUM4.9Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46988MEDIUM5.7Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46980MEDIUM4.8Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46528MEDIUM4.3An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp...
CVE-2024-45741MEDIUM5.4In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.2...
CVE-2024-45740MEDIUM5.4In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged ...
CVE-2024-45739MEDIUM4.9In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for lo...
CVE-2024-45738MEDIUM4.9In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters ...
CVE-2024-45736MEDIUM6.5In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2...
CVE-2024-45735MEDIUM4.3In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform version...
CVE-2024-45734MEDIUM4.3In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" S...
CVE-2024-45732MEDIUM6.5In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2....
CVE-2024-8184MEDIUM6.5There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized u...
CVE-2024-6763MEDIUM5.3Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class,...
CVE-2024-6762MEDIUM6.5Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s...
CVE-2024-41997MEDIUM6.6An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulne...
CVE-2024-9936MEDIUM6.5When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially lea...
CVE-2024-8602MEDIUM6.3When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentB...
CVE-2024-48120MEDIUM5.4X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma...
CVE-2024-48119MEDIUM5.4Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary H...
CVE-2024-46911MEDIUM4.7Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now