2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23566MEDIUM6.5HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead...
CVE-2024-23565MEDIUM5.3HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism ...
CVE-2024-23564CRITICAL9.1HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obta...
CVE-2024-34268HIGH7.1EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow ...
CVE-2024-32389LOW3.5Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attack...
CVE-2024-32387MEDIUM5.7An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv...
CVE-2024-32386HIGH7.3Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at...
CVE-2024-32385MEDIUM4.3An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv...
CVE-2024-58360MEDIUM6.9stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verifica...
CVE-2024-7708HIGH7.5For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is parti...
CVE-2024-56141MEDIUM5Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b0...
CVE-2024-6228HIGH7.5The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value befo...
CVE-2024-1248MEDIUM5.3The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segrega...
CVE-2024-58352HIGH8.7Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitr...
CVE-2024-14037CRITICAL9.8Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote...
CVE-2024-23581HIGH7.8The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized ...
CVE-2024-51454MEDIUM6.1IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 th...
CVE-2024-54178MEDIUM6.5IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authen...
CVE-2024-58351CRITICAL9.8Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig opti...
CVE-2024-27928MEDIUM5.9vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks ...
CVE-2024-24769LOW2.1vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, users can reset their...
CVE-2024-47477MEDIUM6.5Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote un...
CVE-2024-52488CRITICAL9.9Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.
CVE-2024-49269HIGH7.1Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.
CVE-2024-37496MEDIUM4.3Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now