2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32864HIGH8.1Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
CVE-2024-32863HIGH8.8Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)
CVE-2024-7365CRITICAL9.8A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affect...
CVE-2024-7364CRITICAL9.8A vulnerability has been found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. A...
CVE-2024-7363CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Tracking Monitoring Management System 1.0...
CVE-2024-7362CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Tracking Monitoring Management Syste...
CVE-2024-4353MEDIUM4.8Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board ins...
CVE-2024-7361CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Tracking Monitoring Management System 1.0. This vulne...
CVE-2024-7360HIGH8.8A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. Th...
CVE-2024-7256HIGH8.8Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to exe...
CVE-2024-7255HIGH8.8Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perf...
CVE-2024-6990HIGH8.8Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially pe...
CVE-2024-7359MEDIUM6.1A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic....
CVE-2024-7211MEDIUM6.1The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulner...
CVE-2024-41962MEDIUM6.3Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authori...
CVE-2024-23600LOW2.7Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a p...
CVE-2024-6873HIGH8.1It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector b...
CVE-2024-6242HIGH7.3A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot f...
CVE-2024-6040HIGH8.8In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multi...
CVE-2024-41265HIGH7.5A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via t...
CVE-2024-41264HIGH7.5An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostK...
CVE-2024-41260HIGH7.5A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allo...
CVE-2024-41961CRITICAL9.6Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulner...
CVE-2024-41946HIGH7.5REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity...
CVE-2024-41926MEDIUM4.3Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now