2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38371CRITICAL9.8authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when usin...
CVE-2024-37905HIGH8.8authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token me...
CVE-2024-35155MEDIUM6.5IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a de...
CVE-2024-31919HIGH7.5IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service at...
CVE-2024-31912HIGH8.8IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations du...
CVE-2024-6403CRITICAL9.8A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is t...
CVE-2024-6402CRITICAL9.8A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the functi...
CVE-2024-38522MEDIUM6.3Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy ap...
CVE-2024-38521MEDIUM6.1Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored...
CVE-2024-35139MEDIUM5.5IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information fr...
CVE-2024-35137MEDIUM6.2IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileg...
CVE-2024-29039HIGH8.1tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to man...
CVE-2024-38531LOW3.6Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A bui...
CVE-2024-29038LOW3.3tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate ar...
CVE-2024-3816CRITICAL9.8Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar...
CVE-2024-3801MEDIUM6.1Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET h...
CVE-2024-3800MEDIUM6.1Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested fi...
CVE-2024-39704CRITICAL9.8Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to ex...
CVE-2024-37741MEDIUM5.4OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
CVE-2024-5737MEDIUM6.1Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/ht...
CVE-2024-5736HIGH7.5Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to a...
CVE-2024-5735HIGH7.5Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised atta...
CVE-2024-5925MEDIUM6.4The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them...
CVE-2024-5922MEDIUM6.4The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them...
CVE-2024-5662MEDIUM6.4The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline,...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now