2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52899HIGH8.8IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL para...
CVE-2024-11676MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this is...
CVE-2024-11675MEDIUM5.4A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by th...
CVE-2024-53843HIGH8.1@dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend cl...
CVE-2024-11674HIGH8.8A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an...
CVE-2024-11673MEDIUM4.3A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. T...
CVE-2024-53597MEDIUM6.3masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.
CVE-2024-53554HIGH8A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote...
CVE-2024-53102Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-53101MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and ...
CVE-2024-53100MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and d...
CVE-2024-53099HIGH7.1In the Linux kernel, the following vulnerability has been resolved: bpf: Check validity of link->type in bpf_link_show_...
CVE-2024-53098HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/ufence: Prefetch ufence addr to catch bogus ...
CVE-2024-53097MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm: krealloc: Fix MTE false alarm in __do_krealloc ...
CVE-2024-53096HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm: resolve faulty mmap_region() error path behavio...
CVE-2024-53556MEDIUM6.1An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a ...
CVE-2024-50672CRITICAL9.8A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to res...
CVE-2024-50671MEDIUM4.3Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles...
CVE-2024-53268HIGH8.8Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and ...
CVE-2024-53262MEDIUM5.4SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html ...
CVE-2024-53261MEDIUM5.4SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input fro...
CVE-2024-53258MEDIUM5.3Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 o...
CVE-2024-53599MEDIUM5.4A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to exec...
CVE-2024-53255MEDIUM5.4BoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSO...
CVE-2024-52811HIGH8.2The ngtcp2 project is an effort to implement IETF QUIC protocol in C. In affected versions acks are not validated before...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now