2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10922Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-51647. Reason: This candidate is a ...
CVE-2024-51990CRITICAL9.3jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cau...
CVE-2024-51409MEDIUM6.5Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network ...
CVE-2024-48325HIGH8.1Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoC...
CVE-2024-10928MEDIUM6.1A vulnerability was found in MonoCMS up to 20240528. It has been declared as problematic. Affected by this vulnerability...
CVE-2024-10927MEDIUM6.1A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown funct...
CVE-2024-51736CRITICAL9.8Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when a...
CVE-2024-50345MEDIUM6.1symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP s...
CVE-2024-50343LOW3.1symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to ...
CVE-2024-50342MEDIUM4.3symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources s...
CVE-2024-50341LOW3.1symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security co...
CVE-2024-50340HIGH7.3symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. ...
CVE-2024-10941MEDIUM6.5A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. Th...
CVE-2024-10926MEDIUM5.3A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unk...
CVE-2024-51988MEDIUM6.5RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the H...
CVE-2024-51757CRITICAL9.3happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom pr...
CVE-2024-51755LOW2.2Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were ...
CVE-2024-51754LOW2.2Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toStr...
CVE-2024-51751MEDIUM6.5Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadB...
CVE-2024-50315Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2024-50637MEDIUM5.4UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to...
CVE-2024-20540MEDIUM5.4A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) c...
CVE-2024-20539MEDIUM4.8A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond...
CVE-2024-20538MEDIUM6.1A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to co...
CVE-2024-20537MEDIUM6.5A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now