2024 CVE Vulnerabilities

39,152 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-10106LOW3.7A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's...
CVE-2024-37372LOW3.6The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignor...
CVE-2024-54010LOW3.4A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an un...
CVE-2024-53995LOW1.9SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter tak...
CVE-2024-12425LOW2.4Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation ...
CVE-2024-10562LOW2.7The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could ...
CVE-2024-10102LOW2.7The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some ...
CVE-2024-10527LOW3.1The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mo...
CVE-2024-48455LOW2.7An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ...
CVE-2024-51472LOW3.1IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vuln...
CVE-2024-12970LOW3.9Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILG...
CVE-2024-56324LOW2.1GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edi...
CVE-2024-56322LOW2.1GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hi...
CVE-2024-56321LOW3.8GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the ...
CVE-2024-49422LOW3.9Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen...
CVE-2024-56512LOW2.1Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Cont...
CVE-2024-56433LOW3.6shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535...
CVE-2024-56430LOW2.9OpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.
CVE-2024-12014LOW2Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow ...
CVE-2024-44298LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia...
CVE-2024-52589LOW2.7Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin ...
CVE-2024-12801LOW2.4Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on t...
CVE-2024-9101LOW2.1A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the l...
CVE-2024-49820LOW3.7IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensiti...
CVE-2024-42194LOW3.1An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now