2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40570MEDIUM6.5SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_data...
CVE-2024-45380Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-45069Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-45065Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-43422Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-21856Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-25573MEDIUM6.9Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScrip...
CVE-2024-38824HIGH7.5Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory...
CVE-2024-38825MEDIUM6.4The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate whic...
CVE-2024-38823LOW2.7Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
CVE-2024-38822LOW2.7Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another...
CVE-2024-55567MEDIUM6.7Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55....
CVE-2024-7562HIGH7.3A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple In...
CVE-2024-44906MEDIUM6.5uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/...
CVE-2024-44905MEDIUM6.5go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
CVE-2024-56158CRITICAL9.8XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGE...
CVE-2024-9512MEDIUM5.9An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prio...
CVE-2024-35295MEDIUM6.1A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manu...
CVE-2024-1244CRITICAL9.5Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control ...
CVE-2024-1243CRITICAL9.5Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the...
CVE-2024-9062HIGH7.8The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its...
CVE-2024-8270MEDIUM5.5The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Contr...
CVE-2024-7457HIGH7.8The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization mod...
CVE-2024-41505MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section...
CVE-2024-41504MEDIUM6.1Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportuni...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now