2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39742CRITICAL9.8IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configuration...
CVE-2024-6163MEDIUM5.3Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to by...
CVE-2024-37999HIGH7.8A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes...
CVE-2024-27903CRITICAL9.8OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker ...
CVE-2024-27459HIGH7.8The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can ...
CVE-2024-24974HIGH7.5The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allo...
CVE-2024-37389MEDIUM5.4Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context con...
CVE-2024-34603MEDIUM5.5Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location dat...
CVE-2024-34602MEDIUM5.5Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local atta...
CVE-2024-37528MEDIUM5.4IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21...
CVE-2024-31897MEDIUM4.3IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21...
CVE-2024-38330HIGH7.8IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified...
CVE-2024-39723MEDIUM4.6IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physic...
CVE-2024-5711MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inj...
CVE-2024-6539MEDIUM4.8A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unkno...
CVE-2024-3651HIGH7.5A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting vers...
CVE-2024-6229MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the 'Upload Knowledge' feature of stangirard/quivr, affectin...
CVE-2024-40614CRITICAL9.8EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplat...
CVE-2024-40605MEDIUM4.8An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar t...
CVE-2024-40604MEDIUM4.8An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sideba...
CVE-2024-40603MEDIUM4.3An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF t...
CVE-2024-40602MEDIUM4.8An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-le...
CVE-2024-40601MEDIUM6.5An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.
CVE-2024-40600MEDIUM4.8An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar to...
CVE-2024-40599MEDIUM4.8An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now