2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36675CRITICAL9.1LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
CVE-2024-36121CRITICAL9.1 netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP r...
CVE-2024-30889MEDIUM5.4Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execu...
CVE-2024-4220MEDIUM5.3Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumer...
CVE-2024-4219CRITICAL9.1Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, ...
CVE-2024-34364MEDIUM6.5Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror...
CVE-2024-34363HIGH7.5Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the lib...
CVE-2024-34362MEDIUM5.9Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) ...
CVE-2024-32976HIGH7.5Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loo...
CVE-2024-32975HIGH7.5Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()...
CVE-2024-32974HIGH7.5Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHe...
CVE-2024-23326HIGH8.2Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists throug...
CVE-2024-4520HIGH7.5An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 2...
CVE-2024-32464MEDIUM6.1Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment includ...
CVE-2024-30528MEDIUM6.3Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a throu...
CVE-2024-30525HIGH7.3Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor...
CVE-2024-28103CRITICAL9.8Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permis...
CVE-2024-37273CRITICAL9.8An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execut...
CVE-2024-36858CRITICAL9.8An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute...
CVE-2024-36857HIGH7.5Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
CVE-2024-36604CRITICAL9.8Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp functio...
CVE-2024-35672CRITICAL9.8Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19.
CVE-2024-35670CRITICAL9.8Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/...
CVE-2024-34759MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhispe...
CVE-2024-30484HIGH8.8Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builde...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now