2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7037Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-39525HIGH8.7An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju...
CVE-2024-39516HIGH8.7An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS E...
CVE-2024-39515HIGH8.7An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Network...
CVE-2024-38818MEDIUM6.7VMware NSX contains a local privilege escalation vulnerability.  An authenticated malicious actor may exploit this vuln...
CVE-2024-38817MEDIUM6.7VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may ...
CVE-2024-38815MEDIUM4.3VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL an...
CVE-2024-30118MEDIUM5.7HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in...
CVE-2024-7038Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-47833MEDIUM6.5Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine lear...
CVE-2024-47832CRITICAL9.8ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass a...
CVE-2024-47828MEDIUM6.5ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to de...
CVE-2024-47816MEDIUM6.4ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the ...
CVE-2024-47815MEDIUM6IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a var...
CVE-2024-47812MEDIUM6ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface st...
CVE-2024-3656HIGH8.1A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access adminis...
CVE-2024-47813LOW2.9Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s int...
CVE-2024-47763MEDIUM5.5Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with st...
CVE-2024-9473HIGH7.8A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticat...
CVE-2024-9471MEDIUM4.7A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated ...
CVE-2024-9470MEDIUM5.3A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view th...
CVE-2024-9469MEDIUM5.5A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W...
CVE-2024-9468HIGH7.5A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-...
CVE-2024-9467MEDIUM6.1A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context ...
CVE-2024-9466MEDIUM6.5A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated atta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now