2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57708MEDIUM5.7An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __...
CVE-2024-27685HIGH7.1SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi...
CVE-2024-51984MEDIUM6.8An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled ...
CVE-2024-51983HIGH7.5An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP requ...
CVE-2024-51982HIGH7.5An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will cr...
CVE-2024-51981MEDIUM5.3An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that c...
CVE-2024-51980MEDIUM5.3An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open ...
CVE-2024-51979HIGH7.2An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP...
CVE-2024-51978CRITICAL9.8An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password...
CVE-2024-51977MEDIUM5.3An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or t...
CVE-2024-56917HIGH7.1Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.
CVE-2024-37743CRITICAL9.8An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Comp...
CVE-2024-56916MEDIUM6.1In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) d...
CVE-2024-56918MEDIUM6.1In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authen...
CVE-2024-56731CRITICAL9.8Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the ....
CVE-2024-45347CRITICAL9.6An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the val...
CVE-2024-3511MEDIUM4.3An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned f...
CVE-2024-4994HIGH8.1An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting fr...
CVE-2024-4025HIGH7.5A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16...
CVE-2024-7586HIGH7.5An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior...
CVE-2024-53298CRITICAL9.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS expo...
CVE-2024-24916HIGH7.8Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution ...
CVE-2024-45208CRITICAL9.8The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Di...
CVE-2024-54172MEDIUM4.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera...
CVE-2024-54183MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now