2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3115 | MEDIUM | 4.3 | 0.3% | Jun 27, 2024 | An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prio... |
| CVE-2024-2191 | MEDIUM | 5.3 | 0.4% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-1816 | MEDIUM | 5.5 | 0.3% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-1493 | MEDIUM | 6.5 | 0.5% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 pr... |
| CVE-2024-28984 | MEDIUM | 6.1 | 0.3% | Jun 26, 2024 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malici... |
| CVE-2024-28983 | MEDIUM | 6.1 | 0.3% | Jun 26, 2024 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malici... |
| CVE-2024-37571 | MEDIUM | 4.3 | 0.4% | Jun 26, 2024 | Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensiti... |
| CVE-2024-37248 | MEDIUM | 6.5 | 0.3% | Jun 26, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreat... |
| CVE-2024-37247 | MEDIUM | 6.5 | 0.2% | Jun 26, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in twinpicture... |
| CVE-2024-6355 | MEDIUM | 6.9 | 0.4% | Jun 26, 2024 | A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as proble... |
| CVE-2024-23765 | MEDIUM | 4 | 0.2% | Jun 26, 2024 | An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port ... |
| CVE-2024-39242 | MEDIUM | 6.1 | 0.3% | Jun 26, 2024 | A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML vi... |
| CVE-2024-39241 | MEDIUM | 6.1 | 0.3% | Jun 26, 2024 | Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview. |
| CVE-2024-38950 | MEDIUM | 6.5 | 0.4% | Jun 26, 2024 | Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to ... |
| CVE-2024-38949 | MEDIUM | 6.5 | 0.4% | Jun 26, 2024 | Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to ... |
| CVE-2024-38527 | MEDIUM | 5.4 | 0.4% | Jun 26, 2024 | ZenUML is JavaScript-based diagramming tool that requires no server, using Markdown-inspired text definitions and a rend... |
| CVE-2024-38520 | MEDIUM | 5.3 | 0.5% | Jun 26, 2024 | SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enab... |
| CVE-2024-38375 | MEDIUM | 5.3 | 0.3% | Jun 26, 2024 | @fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of sever... |
| CVE-2024-33328 | MEDIUM | 6.1 | 0.4% | Jun 26, 2024 | A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to e... |
| CVE-2024-33327 | MEDIUM | 6.1 | 0.4% | Jun 26, 2024 | A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x... |
| CVE-2024-33326 | MEDIUM | 6.1 | 0.8% | Jun 26, 2024 | A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x a... |
| CVE-2024-35545 | MEDIUM | 6.1 | 0.4% | Jun 26, 2024 | MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2024-39460 | MEDIUM | 4.3 | 0.5% | Jun 26, 2024 | Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of ... |
| CVE-2024-39459 | MEDIUM | 4.3 | 0.4% | Jun 26, 2024 | In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypt... |
| CVE-2024-38272 | MEDIUM | 4.3 | 0.2% | Jun 26, 2024 | There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share W... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now