2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3115MEDIUM4.3An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prio...
CVE-2024-2191MEDIUM5.3An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 p...
CVE-2024-1816MEDIUM5.5An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 p...
CVE-2024-1493MEDIUM6.5An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 pr...
CVE-2024-28984MEDIUM6.1Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malici...
CVE-2024-28983MEDIUM6.1Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malici...
CVE-2024-37571MEDIUM4.3Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensiti...
CVE-2024-37248MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreat...
CVE-2024-37247MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in twinpicture...
CVE-2024-6355MEDIUM6.9A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as proble...
CVE-2024-23765MEDIUM4An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port ...
CVE-2024-39242MEDIUM6.1A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2024-39241MEDIUM6.1Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.
CVE-2024-38950MEDIUM6.5Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to ...
CVE-2024-38949MEDIUM6.5Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to ...
CVE-2024-38527MEDIUM5.4ZenUML is JavaScript-based diagramming tool that requires no server, using Markdown-inspired text definitions and a rend...
CVE-2024-38520MEDIUM5.3SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enab...
CVE-2024-38375MEDIUM5.3@fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of sever...
CVE-2024-33328MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to e...
CVE-2024-33327MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x...
CVE-2024-33326MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x a...
CVE-2024-35545MEDIUM6.1MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2024-39460MEDIUM4.3Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of ...
CVE-2024-39459MEDIUM4.3In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypt...
CVE-2024-38272MEDIUM4.3There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share W...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now