2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20736MEDIUM5.5Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that ...
CVE-2024-20735MEDIUM5.5Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that ...
CVE-2024-20734MEDIUM5.5Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-20733MEDIUM5.5Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerabilit...
CVE-2024-20725MEDIUM5.5Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2024-20724MEDIUM5.5Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2024-20722MEDIUM5.5Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2024-24256MEDIUM5.9SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an ...
CVE-2024-21727MEDIUM6.1XSS vulnerability in DP Calendar component for Joomla.
CVE-2024-0708MEDIUM5.3The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitiv...
CVE-2024-25940MEDIUM6.3`bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected v...
CVE-2024-25559MEDIUM4.7URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request...
CVE-2024-25620MEDIUM6.4Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm cli...
CVE-2024-1471MEDIUM4.8 An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Sec...
CVE-2024-25619MEDIUM4.3Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the ...
CVE-2024-1482MEDIUM6.5An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create n...
CVE-2024-25300MEDIUM4.8A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-0011MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software...
CVE-2024-0010MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS so...
CVE-2024-0009MEDIUM6.3An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enable...
CVE-2024-0007MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-...
CVE-2024-24966MEDIUM5.5 When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly autho...
CVE-2024-23976MEDIUM6When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Applianc...
CVE-2024-23607MEDIUM5.5 A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read fil...
CVE-2024-21782MEDIUM6.7BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but d...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now