2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50839MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management...
CVE-2024-11215MEDIUM6.5Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web ser...
CVE-2024-11209CRITICAL9.8A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the fil...
CVE-2024-11208HIGH8.1A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functi...
CVE-2024-10962HIGH8.8The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...
CVE-2024-8648MEDIUM6.1An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 ...
CVE-2024-7404MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 pr...
CVE-2024-11207MEDIUM5.4A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unk...
CVE-2024-10979HIGH8.8Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitiv...
CVE-2024-10978MEDIUM4.2Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows ...
CVE-2024-10977LOW3.7Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnis...
CVE-2024-10976MEDIUM5.4Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows fro...
CVE-2024-7730HIGH7.8A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input call...
CVE-2024-45670HIGH8.1IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowi...
CVE-2024-45642MEDIUM5.3IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb...
CVE-2024-45099MEDIUM4.8IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb...
CVE-2024-3447MEDIUM6A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_co...
CVE-2024-9693HIGH8.8An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 pr...
CVE-2024-8180MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17....
CVE-2024-10571CRITICAL9.8The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ...
CVE-2024-9472HIGH8.7A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and P...
CVE-2024-5920MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Pan...
CVE-2024-5919MEDIUM6.5A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authent...
CVE-2024-5918MEDIUM4.3An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a...
CVE-2024-5917MEDIUM4.9A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now