2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39753HIGH7.5An modOSCE SQL Injection vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code o...
CVE-2024-10183MEDIUM5.2A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges t...
CVE-2024-9287HIGH7.8A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual en...
CVE-2024-9129CRITICAL9.3In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Ma...
CVE-2024-49211MEDIUM6.1Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.0...
CVE-2024-49210MEDIUM6.1Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A r...
CVE-2024-49209MEDIUM4.3Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to suppo...
CVE-2024-49208LOW3.1Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supportin...
CVE-2024-48708MEDIUM5.4Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action ...
CVE-2024-48707MEDIUM5.4Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit wi...
CVE-2024-48706MEDIUM5.4Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform wi...
CVE-2024-48570HIGH7.5Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports param...
CVE-2024-46538MEDIUM4.8A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-45518HIGH8.8An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41,...
CVE-2024-49373MEDIUM4.3No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an a...
CVE-2024-48929MEDIUM4.2Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and ver...
CVE-2024-48927MEDIUM4.6Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13....
CVE-2024-48926LOW3.1Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions...
CVE-2024-48925MEDIUM6.5Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version...
CVE-2024-48605HIGH7.8An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper v...
CVE-2024-47819HIGH8.7Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in ver...
CVE-2024-46240MEDIUM4.8Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/co...
CVE-2024-8980MEDIUM6.1The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA throug...
CVE-2024-43177CRITICAL9.8IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
CVE-2024-43173LOW3.7IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now