2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6061MEDIUM5.5A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this ...
CVE-2024-37902CRITICAL10DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not pre...
CVE-2024-37896HIGH8.8Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerabi...
CVE-2024-37895MEDIUM5.7Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate th...
CVE-2024-37893MEDIUM5.9Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OA...
CVE-2024-37891MEDIUM6.5 urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the ...
CVE-2024-37890HIGH7.5ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.max...
CVE-2024-37305HIGH8.2oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS...
CVE-2024-6059MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Ingenico Estate Manager 2023. This issue affects...
CVE-2024-38449HIGH7.7A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versi...
CVE-2024-37840HIGH8.8SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Co...
CVE-2024-36543CRITICAL9.8Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to d...
CVE-2024-6058MEDIUM6.1A vulnerability classified as problematic has been found in LabVantage LIMS 2017. This affects an unknown part of the fi...
CVE-2024-6056MEDIUM5.3A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this ...
CVE-2024-37795HIGH7.5A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB inp...
CVE-2024-37794HIGH7.5Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 i...
CVE-2024-37664MEDIUM5.2Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can ...
CVE-2024-37663MEDIUM4.1Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the vic...
CVE-2024-37662MEDIUM6.3TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can...
CVE-2024-37661MEDIUM6.3TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the vi...
CVE-2024-36973HIGH7.8In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the e...
CVE-2024-36527MEDIUM6.5puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter usin...
CVE-2024-36578MEDIUM5.9akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.
CVE-2024-36577HIGH8.3apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.
CVE-2024-36575CRITICAL9.8A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now