2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35220HIGH7.4@fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from th...
CVE-2024-34274LOW3.9OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spo...
CVE-2024-31756HIGH7.8An issue in MarvinTest Solutions Hardware Access Driver v.5.0.3.0 and before and fixed in v.5.0.4.0 allows a local attac...
CVE-2024-35061HIGH7.3NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to...
CVE-2024-35060HIGH7.5An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying...
CVE-2024-35059HIGH7.5An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.
CVE-2024-33525MEDIUM4.3A Stored Cross-site Scripting (XSS) vulnerability in the "Import of organizational units and title of organizational uni...
CVE-2024-31989CRITICAL9Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged po...
CVE-2024-25724HIGH7.3In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Rec...
CVE-2024-4154MEDIUM6.5In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projec...
CVE-2024-35058HIGH7.5An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a cra...
CVE-2024-35057HIGH7.5An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.
CVE-2024-35056CRITICAL9.8NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert f...
CVE-2024-34240MEDIUM6.1QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin func...
CVE-2024-31757HIGH7.8An issue in TeraByte Unlimited Image for Windows v.3.64.0.0 and before and fixed in v.4.0.0.0 allows a local attacker to...
CVE-2024-22275MEDIUM4.9The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the v...
CVE-2024-22274HIGH7.2The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative ...
CVE-2024-22273HIGH7.8The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious...
CVE-2024-36052HIGH7.5RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a differen...
CVE-2024-36039MEDIUM6.3PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict...
CVE-2024-31847MEDIUM6.1An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated...
CVE-2024-31845MEDIUM5.3An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that...
CVE-2024-31844MEDIUM5.3An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases,...
CVE-2024-31840MEDIUM6.5An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source cod...
CVE-2024-27130HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now