2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25980MEDIUM5.3Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other grou...
CVE-2024-25979MEDIUM5.3The URL parameters accepted by forum search were not limited to the allowed parameters.
CVE-2024-1346MEDIUM5.5Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to cal...
CVE-2024-1345MEDIUM5.5Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to per...
CVE-2024-1343MEDIUM5.5A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allow...
CVE-2024-26308MEDIUM5.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache ...
CVE-2024-25710MEDIUM5.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apach...
CVE-2024-26328MEDIUM6An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIO...
CVE-2024-26327MEDIUM5.3An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where ...
CVE-2024-26318MEDIUM6.1Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / ...
CVE-2024-22337MEDIUM5.5IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall...
CVE-2024-22336MEDIUM5.5IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall...
CVE-2024-22335MEDIUM5.5IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall...
CVE-2024-25297MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code a...
CVE-2024-21500MEDIUM6.5All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authe...
CVE-2024-21499MEDIUM4.3All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forward...
CVE-2024-21498MEDIUM5.3All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via ...
CVE-2024-21497MEDIUM6.1Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url paramet...
CVE-2024-21496MEDIUM6.1All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Refe...
CVE-2024-21494MEDIUM5.4All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via t...
CVE-2024-21493MEDIUM5.3All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when...
CVE-2024-20986MEDIUM6.1Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2024-20984MEDIUM4.4Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions...
CVE-2024-20982MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2024-20980MEDIUM5.4Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now