2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36675 | CRITICAL | 9.1 | 1.4% | Jun 4, 2024 | LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function. |
| CVE-2024-36121 | CRITICAL | 9.1 | 0.3% | Jun 4, 2024 | netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP r... |
| CVE-2024-30889 | MEDIUM | 5.4 | 0.5% | Jun 4, 2024 | Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execu... |
| CVE-2024-4220 | MEDIUM | 5.3 | 0.3% | Jun 4, 2024 | Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumer... |
| CVE-2024-4219 | CRITICAL | 9.1 | 0.2% | Jun 4, 2024 | Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, ... |
| CVE-2024-34364 | MEDIUM | 6.5 | 0.5% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror... |
| CVE-2024-34363 | HIGH | 7.5 | 0.7% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the lib... |
| CVE-2024-34362 | MEDIUM | 5.9 | 0.6% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) ... |
| CVE-2024-32976 | HIGH | 7.5 | 0.7% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loo... |
| CVE-2024-32975 | HIGH | 7.5 | 0.7% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()... |
| CVE-2024-32974 | HIGH | 7.5 | 0.7% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHe... |
| CVE-2024-23326 | HIGH | 8.2 | 0.4% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists throug... |
| CVE-2024-4520 | HIGH | 7.5 | 0.5% | Jun 4, 2024 | An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 2... |
| CVE-2024-32464 | MEDIUM | 6.1 | 0.4% | Jun 4, 2024 | Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment includ... |
| CVE-2024-30528 | MEDIUM | 6.3 | 0.3% | Jun 4, 2024 | Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a throu... |
| CVE-2024-30525 | HIGH | 7.3 | 0.3% | Jun 4, 2024 | Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor... |
| CVE-2024-28103 | CRITICAL | 9.8 | 0.7% | Jun 4, 2024 | Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permis... |
| CVE-2024-37273 | CRITICAL | 9.8 | 1.0% | Jun 4, 2024 | An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execut... |
| CVE-2024-36858 | CRITICAL | 9.8 | 3.1% | Jun 4, 2024 | An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute... |
| CVE-2024-36857 | HIGH | 7.5 | 2.1% | Jun 4, 2024 | Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface. |
| CVE-2024-36604 | CRITICAL | 9.8 | 2.0% | Jun 4, 2024 | Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp functio... |
| CVE-2024-35672 | CRITICAL | 9.8 | 0.5% | Jun 4, 2024 | Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19. |
| CVE-2024-35670 | CRITICAL | 9.8 | 0.4% | Jun 4, 2024 | Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/... |
| CVE-2024-34759 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhispe... |
| CVE-2024-30484 | HIGH | 8.8 | 0.3% | Jun 4, 2024 | Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builde... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now