2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9526MEDIUM5.4There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipel...
CVE-2024-8781HIGH8.7Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security...
CVE-2024-11318HIGH7.5An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This ...
CVE-2024-11303HIGH8.7The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 al...
CVE-2024-52318MEDIUM6.1Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31,...
CVE-2024-3370HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software ...
CVE-2024-52317MEDIUM6.5Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response u...
CVE-2024-52316CRITICAL9.8Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication...
CVE-2024-48901MEDIUM4.3A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a re...
CVE-2024-48898MEDIUM4.3A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from othe...
CVE-2024-48897MEDIUM4.3A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds th...
CVE-2024-48896MEDIUM4.3A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' na...
CVE-2024-11319MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS ...
CVE-2024-11023MEDIUM6.1Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncU...
CVE-2024-42392HIGH7.5Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite l...
CVE-2024-42391MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42390MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42389MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42388MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42387MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42386HIGH7.5Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42385HIGH7Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bou...
CVE-2024-42384HIGH7.5Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpect...
CVE-2024-42383CRITICAL9.8Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value ...
CVE-2024-41974HIGH7.1A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for cri...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now