2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20662MEDIUM4.9Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
CVE-2024-20660MEDIUM6.5Microsoft Message Queuing Information Disclosure Vulnerability
CVE-2024-20655MEDIUM6.6Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability
CVE-2024-0340MEDIUM5.5A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initial...
CVE-2024-0226MEDIUM5.4Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a spec...
CVE-2024-22165MEDIUM6.5In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perfor...
CVE-2024-22164MEDIUM4.3In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a deni...
CVE-2024-22370MEDIUM5.4In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
CVE-2024-22368MEDIUM5.5The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a cra...
CVE-2024-21738MEDIUM5.4SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in ...
CVE-2024-21736MEDIUM6.5SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary au...
CVE-2024-21734MEDIUM5.4SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious pag...
CVE-2024-21651MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to ...
CVE-2024-21747MEDIUM4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Co...
CVE-2024-21745MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laybuy Laybuy Paym...
CVE-2024-21744MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapster Technology...
CVE-2024-21645MEDIUM5.3pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified...
CVE-2024-0286MEDIUM6.1A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affec...
CVE-2024-0284MEDIUM6.1A vulnerability was found in Kashipara Food Management System up to 1.0. It has been rated as problematic. This issue af...
CVE-2024-0283MEDIUM6.1A vulnerability was found in Kashipara Food Management System up to 1.0. It has been declared as problematic. This vulne...
CVE-2024-0282MEDIUM6.1A vulnerability was found in Kashipara Food Management System up to 1.0. It has been classified as problematic. This aff...
CVE-2024-0281MEDIUM6.5A vulnerability was found in Kashipara Food Management System up to 1.0 and classified as critical. Affected by this iss...
CVE-2024-0280MEDIUM6.5A vulnerability has been found in Kashipara Food Management System up to 1.0 and classified as critical. Affected by thi...
CVE-2024-0279MEDIUM6.5A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. Affected is ...
CVE-2024-0278MEDIUM6.5A vulnerability, which was classified as critical, has been found in Kashipara Food Management System up to 1.0. This is...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now