2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38366 | CRITICAL | 10 | 17.6% | Jul 1, 2024 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies... |
| CVE-2024-28200 | CRITICAL | 9.8 | 1.9% | Jul 1, 2024 | The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in a... |
| CVE-2024-39251 | CRITICAL | 10 | 0.7% | Jul 1, 2024 | An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers... |
| CVE-2024-39236 | CRITICAL | 9.8 | 0.9% | Jul 1, 2024 | Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. Thi... |
| CVE-2024-38513 | CRITICAL | 9.8 | 0.7% | Jul 1, 2024 | Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a sessio... |
| CVE-2024-38476 | CRITICAL | 9.8 | 41.6% | Jul 1, 2024 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local s... |
| CVE-2024-38475 | CRITICAL | 9.1 | 100.0% | Jul 1, 2024 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to fi... |
| CVE-2024-38474 | CRITICAL | 9.8 | 2.5% | Jul 1, 2024 | Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts i... |
| CVE-2024-36401 | CRITICAL | 9.8 | 99.8% | Jul 1, 2024 | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6... |
| CVE-2024-6376 | CRITICAL | 9.8 | 0.4% | Jul 1, 2024 | MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of e... |
| CVE-2024-21456 | CRITICAL | 9.1 | 0.3% | Jul 1, 2024 | Information Disclosure while parsing beacon frame in STA. |
| CVE-2024-6425 | CRITICAL | 9.1 | 0.5% | Jul 1, 2024 | Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote a... |
| CVE-2024-39017 | CRITICAL | 9.8 | 0.7% | Jul 1, 2024 | agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vul... |
| CVE-2024-39015 | CRITICAL | 9.8 | 0.7% | Jul 1, 2024 | cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allo... |
| CVE-2024-39014 | CRITICAL | 9.8 | 0.7% | Jul 1, 2024 | ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability al... |
| CVE-2024-39013 | CRITICAL | 9.8 | 0.8% | Jul 1, 2024 | 2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows a... |
| CVE-2024-39008 | CRITICAL | 10 | 0.9% | Jul 1, 2024 | robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vuln... |
| CVE-2024-38999 | CRITICAL | 10 | 0.7% | Jul 1, 2024 | jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This v... |
| CVE-2024-38996 | CRITICAL | 9.8 | 1.2% | Jul 1, 2024 | ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.merg... |
| CVE-2024-38993 | CRITICAL | 9.8 | 0.9% | Jul 1, 2024 | rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability ... |
| CVE-2024-20080 | CRITICAL | 9.8 | 0.3% | Jul 1, 2024 | In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to ... |
| CVE-2024-20078 | CRITICAL | 9.8 | 0.3% | Jul 1, 2024 | In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege... |
| CVE-2024-6419 | CRITICAL | 9.8 | 0.6% | Jul 1, 2024 | A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affec... |
| CVE-2024-6416 | CRITICAL | 9.8 | 0.5% | Jun 30, 2024 | A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown... |
| CVE-2024-5926 | CRITICAL | 9.1 | 0.9% | Jun 30, 2024 | A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now