2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-14044MEDIUM6.3A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pc...
CVE-2024-14043MEDIUM6.3A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data...
CVE-2024-14042MEDIUM6.3A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr...
CVE-2024-6541MEDIUM6.8The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy...
CVE-2024-8995MEDIUM4.9Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a...
CVE-2024-10302MEDIUM5.8The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo...
CVE-2024-40683MEDIUM6.3IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,...
CVE-2024-5300MEDIUM5.6An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configura...
CVE-2024-58370MEDIUM6.5SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin...
CVE-2024-58364MEDIUM6.5SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer...
CVE-2024-58363MEDIUM6.3SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clau...
CVE-2024-58358MEDIUM6.9SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owne...
CVE-2024-42214MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method ...
CVE-2024-23578MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) ...
CVE-2024-23577MEDIUM4.3HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary...
CVE-2024-23575MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information ...
CVE-2024-23574MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to ...
CVE-2024-23572MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as...
CVE-2024-23571MEDIUM4.3HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying...
CVE-2024-23570MEDIUM4.3HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta...
CVE-2024-23569MEDIUM4.3HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23568MEDIUM5.3HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th...
CVE-2024-23567MEDIUM4.3HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti...
CVE-2024-23566MEDIUM6.5HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead...
CVE-2024-23565MEDIUM5.3HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now