2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33663MEDIUM6.5python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-...
CVE-2024-33661CRITICAL9.1Portainer before 2.20.0 allows redirects when the target is not index.yaml.
CVE-2024-32868HIGH8.1ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SM...
CVE-2024-32651CRITICAL10changedetection.io is an open source web page change detection, website watcher, restock monitor and notification servic...
CVE-2024-0916CRITICAL10Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3....
CVE-2024-3265MEDIUM4.7The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making ...
CVE-2024-31610MEDIUM6.3File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management Syst...
CVE-2024-31609HIGH7.1Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and...
CVE-2024-32324HIGH7.8Buffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to exe...
CVE-2024-31615CRITICAL9.8ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
CVE-2024-30939MEDIUM6.8An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attac...
CVE-2024-3625HIGH7.3A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. ...
CVE-2024-3624HIGH7.3A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This...
CVE-2024-3623MEDIUM6.5A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in p...
CVE-2024-3622HIGH8.8A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text for...
CVE-2024-3508MEDIUM4.3A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endp...
CVE-2024-32649MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s...
CVE-2024-32648MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Prior to version 0.3.0, default functions ...
CVE-2024-32647MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `c...
CVE-2024-32646MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s...
CVE-2024-32645MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect va...
CVE-2024-2905MEDIUM6.2A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds hav...
CVE-2024-32481MEDIUM5.3Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to ver...
CVE-2024-32467MEDIUM6.5MeterSphere is an open source continuous testing platform. Prior to version 2.10.14-lts, members without space permissio...
CVE-2024-32358HIGH7.5An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now