2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49794 | MEDIUM | 4.3 | 0.1% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau... |
| CVE-2024-49793 | MEDIUM | 5.4 | 0.2% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra... |
| CVE-2024-49792 | MEDIUM | 5.4 | 0.2% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra... |
| CVE-2024-49791 | MEDIUM | 5.4 | 0.2% | Feb 6, 2025 | IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra... |
| CVE-2024-56473 | MEDIUM | 5.3 | 0.3% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log f... |
| CVE-2024-56472 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows auth... |
| CVE-2024-56471 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe... |
| CVE-2024-56470 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe... |
| CVE-2024-38318 | MEDIUM | 6.1 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTM... |
| CVE-2024-38317 | MEDIUM | 4.8 | 0.2% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privilege... |
| CVE-2024-38316 | MEDIUM | 6.5 | 0.4% | Feb 5, 2025 | IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can sen... |
| CVE-2024-57598 | MEDIUM | 6.5 | 0.4% | Feb 5, 2025 | A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() ... |
| CVE-2024-57082 | MEDIUM | 6.5 | 0.3% | Feb 5, 2025 | A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of... |
| CVE-2024-54853 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and e... |
| CVE-2024-7596 | MEDIUM | 6.5 | 0.8% | Feb 5, 2025 | Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing ... |
| CVE-2024-7595 | MEDIUM | 6.5 | 1.5% | Feb 5, 2025 | GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof ... |
| CVE-2024-56135 | MEDIUM | 6.8 | 0.6% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-56134 | MEDIUM | 6.8 | 0.6% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-56133 | MEDIUM | 6.8 | 0.6% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-56132 | MEDIUM | 6.8 | 6.1% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-56131 | MEDIUM | 6.8 | 0.6% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-42207 | MEDIUM | 6 | 0.3% | Feb 5, 2025 | HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from thei... |
| CVE-2024-9097 | MEDIUM | 4.3 | 0.6% | Feb 5, 2025 | ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacke... |
| CVE-2024-52365 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21... |
| CVE-2024-52364 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now