2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4629MEDIUM6.5A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the tim...
CVE-2024-45678MEDIUM4.2Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECD...
CVE-2024-45391HIGH7.5Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prio...
CVE-2024-45390CRITICAL9.8@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within...
CVE-2024-45389MEDIUM5.4Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the locati...
CVE-2024-45180MEDIUM5.4SquaredUp DS for SCOM 6.2.1.11104 allows XSS.
CVE-2024-41434MEDIUM4.3PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows atta...
CVE-2024-45310LOW3.6runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as w...
CVE-2024-45307CRITICAL9.8SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in version...
CVE-2024-43803MEDIUM4.9The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (...
CVE-2024-43413MEDIUM4.8Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr...
CVE-2024-41436HIGH7.5ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
CVE-2024-41435HIGH7.5YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.
CVE-2024-7619Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdra...
CVE-2024-42904MEDIUM6.1A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2024-42903MEDIUM6.5A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows atta...
CVE-2024-42902HIGH8.8An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via ...
CVE-2024-42901MEDIUM4.8A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted ...
CVE-2024-38456HIGH7.8HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and fo...
CVE-2024-43412MEDIUM5.4Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr...
CVE-2024-6119HIGH7.5Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may atte...
CVE-2024-42991HIGH8.1MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CVE-2024-7654MEDIUM6.1An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-dis...
CVE-2024-7346MEDIUM4.8Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perfo...
CVE-2024-7345CRITICAL9.6Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injectio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now