2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-42182LOW2.5BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the appli...
CVE-2024-45687LOW2.4Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Pl...
CVE-2024-22349LOW3.3IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which c...
CVE-2024-54681LOW3.5Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an att...
CVE-2024-37181LOW2.6Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an au...
CVE-2024-57611LOW3.507FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&s...
CVE-2024-57159LOW3.507FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add....
CVE-2024-55503LOW3.3An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_IN...
CVE-2024-53407LOW3.3In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially le...
CVE-2024-40839LOW2.4This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker...
CVE-2024-5198LOW3.3OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with inval...
CVE-2024-57898LOW3.3In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear link ID from bitmap during li...
CVE-2024-29980LOW3.3Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix S...
CVE-2024-29979LOW3.3Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix S...
CVE-2024-55593LOW2.7A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3...
CVE-2024-50564LOW3.3A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versio...
CVE-2024-46665LOW3.7An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may a...
CVE-2024-51491LOW3.3notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specificati...
CVE-2024-42179LOW2.7HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Micr...
CVE-2024-42174LOW3.7HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration o...
CVE-2024-13308LOW3.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Bac...
CVE-2024-13293LOW3.1Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects...
CVE-2024-13261LOW3.5Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affect...
CVE-2024-10106LOW3.7A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's...
CVE-2024-37372LOW3.6The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignor...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now