2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54674MEDIUM6.1app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom cluste...
CVE-2024-51210MEDIUM5.3Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a d...
CVE-2024-50947HIGH7.5An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2024-39219HIGH8.8An issue in Aginode GigaSwitch V5 before version 7.06G allows authenticated attackers with Administrator privileges to u...
CVE-2024-38829LOW3.7A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from ...
CVE-2024-48453CRITICAL9.8An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgr...
CVE-2024-12196MEDIUM6.5Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated...
CVE-2024-12151MEDIUM5Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users ...
CVE-2024-12149HIGH8.1Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0...
CVE-2024-12148MEDIUM4.3Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authen...
CVE-2024-12147HIGH7.1A vulnerability was found in Netgear R6900 1.0.1.26_1.0.20. It has been declared as critical. Affected by this vulnerabi...
CVE-2024-52676MEDIUM5.4Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to Cross Site Scripting (XSS) via /bcc_forum/members/...
CVE-2024-39163HIGH8.8binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.
CVE-2024-20397MEDIUM5.2A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access t...
CVE-2024-54134HIGH8.3A publish-access account was compromised for `@solana/web3.js`, a JavaScript library that is commonly used by Solana dap...
CVE-2024-54132MEDIUM6.3The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that c...
CVE-2024-54002MEDIUM5.3Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software ...
CVE-2024-53614MEDIUM6.5A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrar...
CVE-2024-37575HIGH7.5The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no perm...
CVE-2024-37574HIGH8.2The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to ...
CVE-2024-11643HIGH8.8The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead...
CVE-2024-53140MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netlink: terminate outstanding dump on socket close...
CVE-2024-53139HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sctp: fix possible UAF in sctp_v6_available() A lo...
CVE-2024-53138MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix incorrect page refcounting Th...
CVE-2024-53137MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ARM: fix cacheflush with PAN It seems that the cac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now