2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8395CRITICAL9.8FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside atta...
CVE-2024-45159CRITICAL9.8An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the...
CVE-2024-45158CRITICAL9.8An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_...
CVE-2024-45157MEDIUM5.1An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used...
CVE-2024-7591HIGH7.2Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMa...
CVE-2024-45401HIGH7.1stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in ver...
CVE-2024-42491MEDIUM5.7Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and ...
CVE-2024-45392MEDIUM4.3SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficien...
CVE-2024-44728MEDIUM6.1Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, ...
CVE-2024-44727CRITICAL9.8Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/lo...
CVE-2024-24759CRITICAL9.1MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat ac...
CVE-2024-45589MEDIUM5.9RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts an...
CVE-2024-45176MEDIUM6.1An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web ...
CVE-2024-45175HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It...
CVE-2024-45171HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos...
CVE-2024-45098HIGH8.1IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource mod...
CVE-2024-45097HIGH7.1IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource mod...
CVE-2024-45096MEDIUM6.5IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information thro...
CVE-2024-42885CRITICAL9.1SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id param...
CVE-2024-8445MEDIUM5.7The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authen...
CVE-2024-45178HIGH7.1An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos...
CVE-2024-45173HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning ...
CVE-2024-44587HIGH8.8itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.
CVE-2024-8473MEDIUM6.1Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t...
CVE-2024-8472MEDIUM6.1Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now