2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36574MEDIUM6.3A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflat...
CVE-2024-36573CRITICAL9.8almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index....
CVE-2024-0397HIGH7.4A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext method...
CVE-2024-4032HIGH7.5The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as ...
CVE-2024-36582CRITICAL9.8alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (...
CVE-2024-36581HIGH7.6A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-da...
CVE-2024-1469Rejected reason: ** REJECT ** Duplicate assignment. Please use CVE-2024-0845 instead.
CVE-2024-38470MEDIUM6.1zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par...
CVE-2024-38469MEDIUM6.3zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par...
CVE-2024-37848HIGH8.4SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code vi...
CVE-2024-37625MEDIUM6.1zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search par...
CVE-2024-37624MEDIUM6.1Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inpu...
CVE-2024-37623MEDIUM6.1Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_k...
CVE-2024-37622MEDIUM6.1Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter...
CVE-2024-37621HIGH7.2StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shipp...
CVE-2024-37620MEDIUM6.1PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view...
CVE-2024-37619MEDIUM6.1StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id par...
CVE-2024-37159MEDIUM6.5Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a val...
CVE-2024-37158HIGH8.1Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the cla...
CVE-2024-36583HIGH8.1A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/a...
CVE-2024-36580CRITICAL9.8A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.
CVE-2024-6057CRITICAL9.8Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allo...
CVE-2024-6055MEDIUM4.7Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32....
CVE-2024-5741MEDIUM5.4Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)
CVE-2024-6048CRITICAL9.8Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now