2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56916MEDIUM6.1In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) d...
CVE-2024-56918MEDIUM6.1In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authen...
CVE-2024-56731CRITICAL9.8Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the ....
CVE-2024-45347CRITICAL9.6An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the val...
CVE-2024-3511MEDIUM4.3An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned f...
CVE-2024-4994HIGH8.1An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting fr...
CVE-2024-4025HIGH7.5A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16...
CVE-2024-7586HIGH7.5An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior...
CVE-2024-53298CRITICAL9.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS expo...
CVE-2024-24916HIGH7.8Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution ...
CVE-2024-45208CRITICAL9.8The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Di...
CVE-2024-54172MEDIUM4.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera...
CVE-2024-54183MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnera...
CVE-2024-40570MEDIUM6.5SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_data...
CVE-2024-45380——Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-45069——Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-45065——Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-43422——Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-21856——Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
CVE-2024-25573MEDIUM6.9Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScrip...
CVE-2024-38824HIGH7.5Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory...
CVE-2024-38825MEDIUM6.4The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate whic...
CVE-2024-38823LOW2.7Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
CVE-2024-38822LOW2.7Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another...
CVE-2024-55567MEDIUM6.7Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now