2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-38366CRITICAL10trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies...
CVE-2024-28200CRITICAL9.8The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in a...
CVE-2024-39251CRITICAL10An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers...
CVE-2024-39236CRITICAL9.8Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. Thi...
CVE-2024-38513CRITICAL9.8Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a sessio...
CVE-2024-38476CRITICAL9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local s...
CVE-2024-38475CRITICAL9.1Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to fi...
CVE-2024-38474CRITICAL9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts i...
CVE-2024-36401CRITICAL9.8GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6...
CVE-2024-6376CRITICAL9.8MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of e...
CVE-2024-21456CRITICAL9.1Information Disclosure while parsing beacon frame in STA.
CVE-2024-6425CRITICAL9.1Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote a...
CVE-2024-39017CRITICAL9.8agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vul...
CVE-2024-39015CRITICAL9.8cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allo...
CVE-2024-39014CRITICAL9.8ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability al...
CVE-2024-39013CRITICAL9.82o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows a...
CVE-2024-39008CRITICAL10robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vuln...
CVE-2024-38999CRITICAL10jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This v...
CVE-2024-38996CRITICAL9.8ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.merg...
CVE-2024-38993CRITICAL9.8rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability ...
CVE-2024-20080CRITICAL9.8In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to ...
CVE-2024-20078CRITICAL9.8In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege...
CVE-2024-6419CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affec...
CVE-2024-6416CRITICAL9.8A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown...
CVE-2024-5926CRITICAL9.1A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now