2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52521MEDIUM5.3Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniquen...
CVE-2024-52520MEDIUM6.5Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider...
CVE-2024-52519HIGH8.2Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so ...
CVE-2024-52518MEDIUM5.4Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or admini...
CVE-2024-52517MEDIUM5.9Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API retur...
CVE-2024-52516MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users th...
CVE-2024-52515MEDIUM6.5Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provide...
CVE-2024-50655MEDIUM5.4emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript cod...
CVE-2024-50654HIGH7.5lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quant...
CVE-2024-50653HIGH7.5CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able t...
CVE-2024-44625HIGH8.8Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
CVE-2024-39726HIGH8.2IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity In...
CVE-2024-11248HIGH8.8A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function f...
CVE-2024-11247MEDIUM5.4A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this...
CVE-2024-7865Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2414. Reason: This candidate is a r...
CVE-2024-6413Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2414. Reason: This candidate is a r...
CVE-2024-52555HIGH7.8In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer...
CVE-2024-52526MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-51497MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-51496MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulne...
CVE-2024-51495MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-51494MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-51164CRITICAL9.1Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allo...
CVE-2024-50724CRITICAL9.8KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.
CVE-2024-50652MEDIUM4.3A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now