2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53979HIGH8.2ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like prop...
CVE-2024-53865HIGH8.2zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "...
CVE-2024-53864MEDIUM5.3Ibexa Admin UI Bundle is all the necessary parts to run the Ibexa DXP Back Office interface. The Content name pattern is...
CVE-2024-53861HIGH7.5pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting ...
CVE-2024-53848HIGH7.1check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the bas...
CVE-2024-52810MEDIUM6.9@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerabl...
CVE-2024-52809MEDIUM5.3vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `...
CVE-2024-52801MEDIUM5.3sftpgo is a full-featured and highly configurable event-driven file transfer solution. Server protocols: SFTP, HTTP/S, F...
CVE-2024-52800LOW2.3veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI in...
CVE-2024-52003MEDIUM6.1Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows...
CVE-2024-36616MEDIUM6.5An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of ...
CVE-2024-36615MEDIUM5.9FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding para...
CVE-2024-36611HIGH7.5In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to ad...
CVE-2024-49360HIGH8.4Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticat...
CVE-2024-36624MEDIUM5.4Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.
CVE-2024-36623HIGH8.1moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger mult...
CVE-2024-36622CRITICAL9.8In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vuln...
CVE-2024-36621MEDIUM6.5moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could...
CVE-2024-36620MEDIUM6.5moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-36618MEDIUM6.2FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, po...
CVE-2024-36617MEDIUM6.2FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
CVE-2024-49806CRITICAL9.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp...
CVE-2024-49805CRITICAL9.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp...
CVE-2024-49804HIGH7.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user...
CVE-2024-49803HIGH8.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now