2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47887MEDIUM6.6Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions ...
CVE-2024-47836MEDIUM4.3Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability all...
CVE-2024-47522HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-47188HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-47187HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-45797HIGH7.5LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unboun...
CVE-2024-45796MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-45795HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-41128MEDIUM6.6Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions ...
CVE-2024-9143MEDIUM4.3Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial ...
CVE-2024-4692LOW2.4Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allow...
CVE-2024-4690HIGH8Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ...
CVE-2024-4211LOW2.4Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allow...
CVE-2024-4189HIGH8Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ...
CVE-2024-4184HIGH8Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ...
CVE-2024-46606MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to ...
CVE-2024-46605MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to ...
CVE-2024-45072MEDIUM5.5IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when process...
CVE-2024-45071MEDIUM4.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p...
CVE-2024-38814HIGH8.8An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated ...
CVE-2024-20512MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) c...
CVE-2024-20463HIGH7.1A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al...
CVE-2024-20462MEDIUM5.5A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter fir...
CVE-2024-20461MEDIUM6A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, ...
CVE-2024-20460MEDIUM6.1A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now