2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35627 | MEDIUM | 6.1 | 1.0% | May 22, 2024 | tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data... |
| CVE-2024-31904 | MEDIUM | 6.5 | 0.5% | May 22, 2024 | IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an au... |
| CVE-2024-31893 | MEDIUM | 4.3 | 0.3% | May 22, 2024 | IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar inf... |
| CVE-2024-25737 | MEDIUM | 5.4 | 0.4% | May 22, 2024 | A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open ... |
| CVE-2024-31617 | MEDIUM | 5.3 | 0.4% | May 22, 2024 | OpenLiteSpeed before 1.8.1 mishandles chunked encoding. |
| CVE-2024-29421 | MEDIUM | 6.2 | 0.2% | May 22, 2024 | xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to... |
| CVE-2024-5166 | MEDIUM | 6.5 | 0.2% | May 22, 2024 | An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users... |
| CVE-2024-20363 | MEDIUM | 5.8 | 0.4% | May 22, 2024 | Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that ... |
| CVE-2024-20361 | MEDIUM | 5.8 | 0.4% | May 22, 2024 | A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) ... |
| CVE-2024-20355 | MEDIUM | 5 | 0.3% | May 22, 2024 | A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive ... |
| CVE-2024-20293 | MEDIUM | 5.8 | 0.4% | May 22, 2024 | A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software an... |
| CVE-2024-20261 | MEDIUM | 5.8 | 0.4% | May 22, 2024 | A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Def... |
| CVE-2024-35362 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php. |
| CVE-2024-29392 | MEDIUM | 5.4 | 0.4% | May 22, 2024 | Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController. |
| CVE-2024-3926 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-35561 | MEDIUM | 5.4 | 0.2% | May 22, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add... |
| CVE-2024-35560 | MEDIUM | 4.3 | 0.2% | May 22, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del... |
| CVE-2024-35557 | MEDIUM | 5.5 | 0.2% | May 22, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi... |
| CVE-2024-35555 | MEDIUM | 6.3 | 0.2% | May 22, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mud... |
| CVE-2024-35554 | MEDIUM | 5.4 | 0.2% | May 22, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mud... |
| CVE-2024-35551 | MEDIUM | 4.3 | 0.2% | May 22, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mud... |
| CVE-2024-35550 | MEDIUM | 6.3 | 0.2% | May 22, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mud... |
| CVE-2024-35475 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12... |
| CVE-2024-4261 | MEDIUM | 5.4 | 0.3% | May 22, 2024 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-36010 | MEDIUM | 5.5 | 0.2% | May 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: igb: Fix string truncation warnings in igb_set_fw_v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now