2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53457MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows ...
CVE-2024-12064Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-53523HIGH7.5JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file functi...
CVE-2024-53589HIGH8.4GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex forma...
CVE-2024-53442CRITICAL9.8whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.
CVE-2024-41579CRITICAL9.8DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause ...
CVE-2024-11148HIGH8.7In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when ha...
CVE-2024-10933MEDIUM5.5In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid ...
CVE-2024-12235HIGH8.8A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared a...
CVE-2024-12130HIGH7.8An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threa...
CVE-2024-11158HIGH8.5An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a...
CVE-2024-11156HIGH7.8An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a th...
CVE-2024-11155HIGH8.5A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat acto...
CVE-2024-54128MEDIUM4.6Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a f...
CVE-2024-53846MEDIUM5.5OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainl...
CVE-2024-53490HIGH7.5Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.
CVE-2024-12234CRITICAL9.8A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Aff...
CVE-2024-12233CRITICAL9.8A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects ...
CVE-2024-54130CRITICAL9.2The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A se...
CVE-2024-54129CRITICAL9.2The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vu...
CVE-2024-54001MEDIUM5.5Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the...
CVE-2024-53857HIGH7.5rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vul...
CVE-2024-53856HIGH7.5rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by provi...
CVE-2024-53472HIGH8.8WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2024-53471MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now