2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39243CRITICAL9.8An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/adm...
CVE-2024-39242MEDIUM6.1A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2024-39241MEDIUM6.1Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.
CVE-2024-38950MEDIUM6.5Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to ...
CVE-2024-38949MEDIUM6.5Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to ...
CVE-2024-38527MEDIUM5.4ZenUML is JavaScript-based diagramming tool that requires no server, using Markdown-inspired text definitions and a rend...
CVE-2024-38520MEDIUM5.3SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enab...
CVE-2024-38375MEDIUM5.3@fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of sever...
CVE-2024-33329HIGH7.5A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access interna...
CVE-2024-33328MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to e...
CVE-2024-33327MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x...
CVE-2024-33326MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x a...
CVE-2024-35545MEDIUM6.1MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2024-6354HIGH7.2Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows a...
CVE-2024-39460MEDIUM4.3Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of ...
CVE-2024-39459MEDIUM4.3In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypt...
CVE-2024-39458LOW3.1When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message c...
CVE-2024-38272MEDIUM4.3There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share W...
CVE-2024-38271MEDIUM4.8There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporar...
CVE-2024-25637MEDIUM5.4October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not ...
CVE-2024-6349Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-4604MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Ma...
CVE-2024-4228CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ...
CVE-2024-6344LOW2.4A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an ...
CVE-2024-37252CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subs...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now