2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22021MEDIUM4.3Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retri...
CVE-2024-1267MEDIUM6.1A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by...
CVE-2024-1266MEDIUM6.1A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vuln...
CVE-2024-1265MEDIUM4.8A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an u...
CVE-2024-0971MEDIUM6.5 A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter sca...
CVE-2024-0955MEDIUM4.8 A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus a...
CVE-2024-24255MEDIUM4.2A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows...
CVE-2024-24254MEDIUM4.2PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condi...
CVE-2024-1258MEDIUM5.9A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerab...
CVE-2024-22241MEDIUM4.8Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can ...
CVE-2024-22240MEDIUM4.9Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may explo...
CVE-2024-22238MEDIUM4.8Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may ...
CVE-2024-1257MEDIUM6.1A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of t...
CVE-2024-1256MEDIUM4.3A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of...
CVE-2024-22331MEDIUM5.5IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM...
CVE-2024-24291MEDIUM6.1An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a c...
CVE-2024-23344MEDIUM6.5Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get ac...
CVE-2024-24594MEDIUM5.4A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform ...
CVE-2024-0911MEDIUM5.5A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into proce...
CVE-2024-0690MEDIUM5.5An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in...
CVE-2024-24943MEDIUM5.5In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
CVE-2024-24942MEDIUM5.3In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
CVE-2024-24941MEDIUM5.3In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an i...
CVE-2024-24940MEDIUM4.3In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
CVE-2024-24939MEDIUM5.3In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now