2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7318MEDIUM4.8A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period i...
CVE-2024-7260MEDIUM6.1An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and ...
CVE-2024-45411HIGH8.6Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user...
CVE-2024-45296HIGH7.5path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular exp...
CVE-2024-42759MEDIUM6.3An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente...
CVE-2024-24510MEDIUM6.1Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via t...
CVE-2024-44849CRITICAL9.8Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
CVE-2024-44335HIGH8.8D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04....
CVE-2024-44334HIGH8.8D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24....
CVE-2024-45406MEDIUM4.8Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fie...
CVE-2024-44333HIGH8.8D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24....
CVE-2024-8605MEDIUM5.4A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affect...
CVE-2024-8604MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects...
CVE-2024-44721CRITICAL9.8SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
CVE-2024-44720HIGH7.5SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.
CVE-2024-8373MEDIUM4.3Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to ...
CVE-2024-8372MEDIUM4.3Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source...
CVE-2024-8042LOW3.1Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues wher...
CVE-2024-45041HIGH8.8External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secr...
CVE-2024-40643CRITICAL9.6Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by ...
CVE-2024-7015CRITICAL9.8Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authent...
CVE-2024-44375HIGH7.5D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.
CVE-2024-8601MEDIUM6.5This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on c...
CVE-2024-6572HIGH7.4Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk...
CVE-2024-37288HIGH8.8A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document con...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now