2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-49794MEDIUM4.3IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2024-49793MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-49792MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-49791MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2024-56473MEDIUM5.3IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log f...
CVE-2024-56472MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows auth...
CVE-2024-56471MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe...
CVE-2024-56470MEDIUM5.4IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authe...
CVE-2024-38318MEDIUM6.1IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTM...
CVE-2024-38317MEDIUM4.8IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privilege...
CVE-2024-38316MEDIUM6.5IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can sen...
CVE-2024-57598MEDIUM6.5A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() ...
CVE-2024-57082MEDIUM6.5A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of...
CVE-2024-54853MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and e...
CVE-2024-7596MEDIUM6.5Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing ...
CVE-2024-7595MEDIUM6.5GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof ...
CVE-2024-56135MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-56134MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-56133MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-56132MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-56131MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-42207MEDIUM6HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from thei...
CVE-2024-9097MEDIUM4.3ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacke...
CVE-2024-52365MEDIUM5.4IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21...
CVE-2024-52364MEDIUM5.4IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now