2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38817MEDIUM6.7VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may ...
CVE-2024-38815MEDIUM4.3VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL an...
CVE-2024-30118MEDIUM5.7HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in...
CVE-2024-47833MEDIUM6.5Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine lear...
CVE-2024-47828MEDIUM6.5ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to de...
CVE-2024-47816MEDIUM6.4ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the ...
CVE-2024-47815MEDIUM6IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a var...
CVE-2024-47812MEDIUM6ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface st...
CVE-2024-47763MEDIUM5.5Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with st...
CVE-2024-9471MEDIUM4.7A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated ...
CVE-2024-9470MEDIUM5.3A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view th...
CVE-2024-9469MEDIUM5.5A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W...
CVE-2024-9467MEDIUM6.1A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context ...
CVE-2024-9466MEDIUM6.5A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated atta...
CVE-2024-9464MEDIUM6.5An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary...
CVE-2024-42988MEDIUM4.3Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows auth...
CVE-2024-9675MEDIUM4.4A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are ...
CVE-2024-9671MEDIUM5.3A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is k...
CVE-2024-7294MEDIUM6.5In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous...
CVE-2024-47673MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pause TCM when the firmware is ...
CVE-2024-47671MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: prevent kernel-usb-infoleak The syzbo...
CVE-2024-47669MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix state management in error path of log w...
CVE-2024-47668MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Fix rare race in __genrad...
CVE-2024-47667MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI: keystone: Add workaround for Errata #i2037 (AM...
CVE-2024-47666MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now