2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24198HIGH7.5smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c.
CVE-2024-24195HIGH7.5robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c.
CVE-2024-24194HIGH7.5robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-p...
CVE-2024-24192CRITICAL9.1robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-inser...
CVE-2024-22525MEDIUM5.5dnspod-sr 0dfbd37 contains a SEGV.
CVE-2024-22524MEDIUM5.5dnspod-sr 0dfbd37 is vulnerable to buffer overflow.
CVE-2024-36795MEDIUM4Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories em...
CVE-2024-32752CRITICAL9.1The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with I...
CVE-2024-22074CRITICAL9.8Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5....
CVE-2024-5609Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6966. Reason: This candidate is a r...
CVE-2024-5552HIGH7.5kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expr...
CVE-2024-5550MEDIUM5.3In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system pa...
CVE-2024-5480Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5478MEDIUM6.1A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of luna...
CVE-2024-5328CRITICAL9.3A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the e...
CVE-2024-5307LOW3.3Kofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows r...
CVE-2024-5306HIGH7.8Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote...
CVE-2024-5305HIGH7.8Kofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-5304HIGH7.8Kofax Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2024-5278MEDIUM6.1gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of ...
CVE-2024-5248MEDIUM6.5In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in ...
CVE-2024-5225HIGH7.2An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` en...
CVE-2024-5206MEDIUM4.7A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to ...
CVE-2024-5187HIGH8.8A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for a...
CVE-2024-5186HIGH7.2A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now