2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36574 | MEDIUM | 6.3 | 0.4% | Jun 17, 2024 | A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflat... |
| CVE-2024-36573 | CRITICAL | 9.8 | 0.7% | Jun 17, 2024 | almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.... |
| CVE-2024-0397 | HIGH | 7.4 | 0.8% | Jun 17, 2024 | A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext method... |
| CVE-2024-4032 | HIGH | 7.5 | 1.0% | Jun 17, 2024 | The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as ... |
| CVE-2024-36582 | CRITICAL | 9.8 | 0.6% | Jun 17, 2024 | alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (... |
| CVE-2024-36581 | HIGH | 7.6 | 0.5% | Jun 17, 2024 | A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-da... |
| CVE-2024-1469 | — | — | — | Jun 17, 2024 | Rejected reason: ** REJECT ** Duplicate assignment. Please use CVE-2024-0845 instead. |
| CVE-2024-38470 | MEDIUM | 6.1 | 0.3% | Jun 17, 2024 | zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par... |
| CVE-2024-38469 | MEDIUM | 6.3 | 0.3% | Jun 17, 2024 | zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par... |
| CVE-2024-37848 | HIGH | 8.4 | 0.2% | Jun 17, 2024 | SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code vi... |
| CVE-2024-37625 | MEDIUM | 6.1 | 0.3% | Jun 17, 2024 | zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par... |
| CVE-2024-37624 | MEDIUM | 6.1 | 0.3% | Jun 17, 2024 | Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inpu... |
| CVE-2024-37623 | MEDIUM | 6.1 | 0.3% | Jun 17, 2024 | Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_k... |
| CVE-2024-37622 | MEDIUM | 6.1 | 0.3% | Jun 17, 2024 | Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter... |
| CVE-2024-37621 | HIGH | 7.2 | 0.7% | Jun 17, 2024 | StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shipp... |
| CVE-2024-37620 | MEDIUM | 6.1 | 0.3% | Jun 17, 2024 | PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view... |
| CVE-2024-37619 | MEDIUM | 6.1 | 0.4% | Jun 17, 2024 | StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id par... |
| CVE-2024-37159 | MEDIUM | 6.5 | 0.3% | Jun 17, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a val... |
| CVE-2024-37158 | HIGH | 8.1 | 0.4% | Jun 17, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the cla... |
| CVE-2024-36583 | HIGH | 8.1 | 0.6% | Jun 17, 2024 | A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/a... |
| CVE-2024-36580 | CRITICAL | 9.8 | 0.8% | Jun 17, 2024 | A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code. |
| CVE-2024-6057 | CRITICAL | 9.8 | 0.9% | Jun 17, 2024 | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allo... |
| CVE-2024-6055 | MEDIUM | 4.7 | 0.5% | Jun 17, 2024 | Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.... |
| CVE-2024-5741 | MEDIUM | 5.4 | 0.3% | Jun 17, 2024 | Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL) |
| CVE-2024-6048 | CRITICAL | 9.8 | 0.7% | Jun 17, 2024 | Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now