2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58343MEDIUM4.3Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie d...
CVE-2024-8010HIGH7.5The component accepts XML input through the publisher without disabling external entity resolution. This allows maliciou...
CVE-2024-4867MEDIUM5.4The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or p...
CVE-2024-10242MEDIUM6.1The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. ...
CVE-2024-2374CRITICAL9.1The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the ...
CVE-2024-53412HIGH8.4Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shel...
CVE-2024-33618HIGH7.5Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessiv...
CVE-2024-23104MEDIUM4.3An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 t...
CVE-2024-9168——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-1490HIGH7.2An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management...
CVE-2024-36058CRITICAL9.8The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fail...
CVE-2024-36057CRITICAL9.8Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code ex...
CVE-2024-14032HIGH7.8Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that ...
CVE-2024-14033HIGH8.7Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. A...
CVE-2024-14034CRITICAL9.8Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) managem...
CVE-2024-44303HIGH7.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be ...
CVE-2024-44286HIGH7.5This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with ...
CVE-2024-44250HIGH8.2A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be...
CVE-2024-44219HIGH7.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious a...
CVE-2024-40858HIGH7.1A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be...
CVE-2024-40849HIGH7.5A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able...
CVE-2024-43028CRITICAL9.8A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to exe...
CVE-2024-40489CRITICAL9.8There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows a...
CVE-2024-53828MEDIUM5.3Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large v...
CVE-2024-58342MEDIUM6.1XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now