2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33663 | MEDIUM | 6.5 | 0.3% | Apr 26, 2024 | python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-... |
| CVE-2024-33661 | CRITICAL | 9.1 | 0.6% | Apr 26, 2024 | Portainer before 2.20.0 allows redirects when the target is not index.yaml. |
| CVE-2024-32868 | HIGH | 8.1 | 0.5% | Apr 26, 2024 | ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SM... |
| CVE-2024-32651 | CRITICAL | 10 | 83.7% | Apr 26, 2024 | changedetection.io is an open source web page change detection, website watcher, restock monitor and notification servic... |
| CVE-2024-0916 | CRITICAL | 10 | 1.0% | Apr 25, 2024 | Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.... |
| CVE-2024-3265 | MEDIUM | 4.7 | 0.4% | Apr 25, 2024 | The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making ... |
| CVE-2024-31610 | MEDIUM | 6.3 | 0.4% | Apr 25, 2024 | File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management Syst... |
| CVE-2024-31609 | HIGH | 7.1 | 0.4% | Apr 25, 2024 | Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and... |
| CVE-2024-32324 | HIGH | 7.8 | 0.3% | Apr 25, 2024 | Buffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to exe... |
| CVE-2024-31615 | CRITICAL | 9.8 | 0.7% | Apr 25, 2024 | ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. |
| CVE-2024-30939 | MEDIUM | 6.8 | 0.4% | Apr 25, 2024 | An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attac... |
| CVE-2024-3625 | HIGH | 7.3 | 0.3% | Apr 25, 2024 | A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. ... |
| CVE-2024-3624 | HIGH | 7.3 | 0.3% | Apr 25, 2024 | A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This... |
| CVE-2024-3623 | MEDIUM | 6.5 | 0.4% | Apr 25, 2024 | A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in p... |
| CVE-2024-3622 | HIGH | 8.8 | 0.5% | Apr 25, 2024 | A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text for... |
| CVE-2024-3508 | MEDIUM | 4.3 | 0.5% | Apr 25, 2024 | A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endp... |
| CVE-2024-32649 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s... |
| CVE-2024-32648 | MEDIUM | 5.3 | 0.4% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Prior to version 0.3.0, default functions ... |
| CVE-2024-32647 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `c... |
| CVE-2024-32646 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s... |
| CVE-2024-32645 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect va... |
| CVE-2024-2905 | MEDIUM | 6.2 | 0.3% | Apr 25, 2024 | A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds hav... |
| CVE-2024-32481 | MEDIUM | 5.3 | 0.8% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to ver... |
| CVE-2024-32467 | MEDIUM | 6.5 | 0.5% | Apr 25, 2024 | MeterSphere is an open source continuous testing platform. Prior to version 2.10.14-lts, members without space permissio... |
| CVE-2024-32358 | HIGH | 7.5 | 0.7% | Apr 25, 2024 | An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now