2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39124MEDIUM5.4In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
CVE-2024-32981MEDIUM5.4Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor ...
CVE-2024-29885MEDIUM4.3silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports ...
CVE-2024-40420Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-36694. Reason: This record is a duplicate of CVE-2024-...
CVE-2024-28796MEDIUM5.4IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to...
CVE-2024-40641HIGH7.4Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way t...
CVE-2024-40640LOW2.9vodozemac is an open source implementation of Olm and Megolm in pure Rust. Versions before 0.7.0 of vodozemac use a non...
CVE-2024-40639Rejected reason: This CVE is a duplicate of another CVE.
CVE-2024-40636MEDIUM5.3Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud...
CVE-2024-40633MEDIUM5.3Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/ad...
CVE-2024-38447HIGH8.1NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft rep...
CVE-2024-38870LOW3.5Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, ...
CVE-2024-38446MEDIUM6.5NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the...
CVE-2024-20435HIGH7.8A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to exe...
CVE-2024-20429HIGH7.2A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authentic...
CVE-2024-20419CRITICAL10A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth...
CVE-2024-20416MEDIUM6.5A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated,...
CVE-2024-20401CRITICAL9.8A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unau...
CVE-2024-20400MEDIUM4.7A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote ...
CVE-2024-20396MEDIUM6.5A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain acce...
CVE-2024-20395HIGH7.3A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacke...
CVE-2024-20323HIGH7.5A vulnerability in Cisco Intelligent Node (iNode) Software could allow an unauthenticated, remote attacker to hijack the...
CVE-2024-20296HIGH7.2A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2024-6830HIGH7.5A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. A...
CVE-2024-6834CRITICAL9A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Z...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now