2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39173CRITICAL9.8calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function ...
CVE-2024-39090MEDIUM6.1The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forger...
CVE-2024-30126MEDIUM4.7HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malic...
CVE-2024-5321MEDIUM6.1A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read contai...
CVE-2024-39152Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-6655. Reason: This record is a reservation duplicate ...
CVE-2024-38806LOW3.9Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloud...
CVE-2024-5625MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console...
CVE-2024-30125MEDIUM6.2HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the s...
CVE-2024-0857CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software...
CVE-2024-5620MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Cons...
CVE-2024-5619CRITICAL9.6Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allo...
CVE-2024-5618CRITICAL9.9Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console...
CVE-2024-40648MEDIUM5.4matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method...
CVE-2024-40647MEDIUM5.3sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variabl...
CVE-2024-40644MEDIUM6.8gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another...
CVE-2024-40629CRITICAL9.8JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an...
CVE-2024-40628CRITICAL9.1JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an...
CVE-2024-39911CRITICAL9.81Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent...
CVE-2024-39907CRITICAL9.81Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of t...
CVE-2024-38302MEDIUM5.7Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (St...
CVE-2024-30473MEDIUM6.5Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privile...
CVE-2024-34013HIGH7.8Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True ...
CVE-2024-31143HIGH7.5An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. ...
CVE-2024-29178HIGH8.8On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution...
CVE-2024-6504MEDIUM5.3Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with netw...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now