2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6061 | MEDIUM | 5.5 | 0.4% | Jun 17, 2024 | A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this ... |
| CVE-2024-37902 | CRITICAL | 10 | 0.7% | Jun 17, 2024 | DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not pre... |
| CVE-2024-37896 | HIGH | 8.8 | 0.5% | Jun 17, 2024 | Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerabi... |
| CVE-2024-37895 | MEDIUM | 5.7 | 0.5% | Jun 17, 2024 | Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate th... |
| CVE-2024-37893 | MEDIUM | 5.9 | 0.6% | Jun 17, 2024 | Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OA... |
| CVE-2024-37891 | MEDIUM | 6.5 | 1.1% | Jun 17, 2024 | urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the ... |
| CVE-2024-37890 | HIGH | 7.5 | 1.4% | Jun 17, 2024 | ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.max... |
| CVE-2024-37305 | HIGH | 8.2 | 0.4% | Jun 17, 2024 | oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS... |
| CVE-2024-6059 | MEDIUM | 4.8 | 0.4% | Jun 17, 2024 | A vulnerability, which was classified as problematic, has been found in Ingenico Estate Manager 2023. This issue affects... |
| CVE-2024-38449 | HIGH | 7.7 | 1.0% | Jun 17, 2024 | A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versi... |
| CVE-2024-37840 | HIGH | 8.8 | 0.5% | Jun 17, 2024 | SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Co... |
| CVE-2024-36543 | CRITICAL | 9.8 | 0.5% | Jun 17, 2024 | Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to d... |
| CVE-2024-6058 | MEDIUM | 6.1 | 0.4% | Jun 17, 2024 | A vulnerability classified as problematic has been found in LabVantage LIMS 2017. This affects an unknown part of the fi... |
| CVE-2024-6056 | MEDIUM | 5.3 | 0.7% | Jun 17, 2024 | A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this ... |
| CVE-2024-37795 | HIGH | 7.5 | 0.5% | Jun 17, 2024 | A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB inp... |
| CVE-2024-37794 | HIGH | 7.5 | 0.5% | Jun 17, 2024 | Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 i... |
| CVE-2024-37664 | MEDIUM | 5.2 | 0.4% | Jun 17, 2024 | Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can ... |
| CVE-2024-37663 | MEDIUM | 4.1 | 0.3% | Jun 17, 2024 | Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the vic... |
| CVE-2024-37662 | MEDIUM | 6.3 | 0.4% | Jun 17, 2024 | TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can... |
| CVE-2024-37661 | MEDIUM | 6.3 | 0.3% | Jun 17, 2024 | TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the vi... |
| CVE-2024-36973 | HIGH | 7.8 | 0.2% | Jun 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the e... |
| CVE-2024-36527 | MEDIUM | 6.5 | 2.6% | Jun 17, 2024 | puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter usin... |
| CVE-2024-36578 | MEDIUM | 5.9 | 0.2% | Jun 17, 2024 | akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js. |
| CVE-2024-36577 | HIGH | 8.3 | 0.4% | Jun 17, 2024 | apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty. |
| CVE-2024-36575 | CRITICAL | 9.8 | 0.6% | Jun 17, 2024 | A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now