2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57427MEDIUM6.1PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improper...
CVE-2024-43779MEDIUM6.5An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. ...
CVE-2024-13614MEDIUM5.3Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Ligh...
CVE-2024-49800MEDIUM6.5IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.
CVE-2024-49798MEDIUM4.3IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message i...
CVE-2024-49797MEDIUM5.9IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable...
CVE-2024-49796MEDIUM5.4IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi...
CVE-2024-49795MEDIUM4.3IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2024-49794MEDIUM4.3IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2024-49793MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-49792MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-49791MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-56473MEDIUM5.3IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log f...
CVE-2024-56472MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows auth...
CVE-2024-56471MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe...
CVE-2024-56470MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe...
CVE-2024-38318MEDIUM6.1IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTM...
CVE-2024-38317MEDIUM4.8IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privilege...
CVE-2024-38316MEDIUM6.5IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can sen...
CVE-2024-57598MEDIUM6.5A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() ...
CVE-2024-57082MEDIUM6.5A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of...
CVE-2024-54853MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and e...
CVE-2024-7596MEDIUM6.5Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing ...
CVE-2024-7595MEDIUM6.5GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof ...
CVE-2024-56135MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now