2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58255MEDIUM6.7EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com...
CVE-2024-42048MEDIUM6.5OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all...
CVE-2024-56339HIGH7.5IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a re...
CVE-2024-55401MEDIUM6.5An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.
CVE-2024-52680MEDIUM6.1EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.
CVE-2024-55402MEDIUM5.34C Strategies Exonaut before v22.4 was discovered to contain an access control issue.
CVE-2024-55399MEDIUM6.54C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).
CVE-2024-55398MEDIUM6.54C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.
CVE-2024-8244LOW3.7The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are ...
CVE-2024-52885MEDIUM5.4The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticat...
CVE-2024-52890MEDIUM6.1IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to n...
CVE-2024-45183MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPE...
CVE-2024-51775MEDIUM5.3Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server...
CVE-2024-52279MEDIUM5.3Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not ac...
CVE-2024-41177MEDIUM6.1Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: befo...
CVE-2024-13978LOW2.5A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is...
CVE-2024-34327MEDIUM6.5Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the passwor...
CVE-2024-34328MEDIUM6.3An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.
CVE-2024-11478Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-48916HIGH8.1Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an ...
CVE-2024-45955HIGH7.3Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
CVE-2024-45515MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in...
CVE-2024-43018MEDIUM6.4Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters ar...
CVE-2024-52894MEDIUM4.9IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...
CVE-2024-51473HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 1...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now