2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31993 | MEDIUM | 4.5 | 0.4% | Apr 19, 2024 | Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an imag... |
| CVE-2024-31992 | MEDIUM | 6.5 | 0.7% | Apr 19, 2024 | Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c... |
| CVE-2024-31991 | LOW | 3.5 | 0.3% | Apr 19, 2024 | Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c... |
| CVE-2024-31584 | MEDIUM | 5.5 | 0.4% | Apr 19, 2024 | Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.... |
| CVE-2024-30974 | HIGH | 7.3 | 0.3% | Apr 19, 2024 | SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId paramete... |
| CVE-2024-22905 | HIGH | 7 | 0.4% | Apr 19, 2024 | Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted s... |
| CVE-2024-1681 | MEDIUM | 5.3 | 0.6% | Apr 19, 2024 | corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake lo... |
| CVE-2024-32652 | HIGH | 7.5 | 0.9% | Apr 19, 2024 | The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs... |
| CVE-2024-31450 | MEDIUM | 6.5 | 1.0% | Apr 19, 2024 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast app... |
| CVE-2024-3979 | MEDIUM | 4.4 | 0.2% | Apr 19, 2024 | A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this is... |
| CVE-2024-31547 | CRITICAL | 9.1 | 0.6% | Apr 19, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_ite... |
| CVE-2024-31546 | CRITICAL | 9.8 | 0.7% | Apr 19, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_d... |
| CVE-2024-31552 | HIGH | 7.1 | 0.2% | Apr 19, 2024 | CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitr... |
| CVE-2024-2440 | MEDIUM | 5.9 | 0.5% | Apr 19, 2024 | A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository ... |
| CVE-2024-29991 | MEDIUM | 5 | 0.6% | Apr 19, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2024-32650 | HIGH | 7.5 | 0.9% | Apr 19, 2024 | Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop... |
| CVE-2024-32409 | HIGH | 7.1 | 0.7% | Apr 19, 2024 | An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. |
| CVE-2024-32206 | MEDIUM | 4.6 | 0.5% | Apr 19, 2024 | A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows at... |
| CVE-2024-31846 | HIGH | 7.5 | 0.7% | Apr 19, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access ... |
| CVE-2024-31841 | HIGH | 7.5 | 0.8% | Apr 19, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthent... |
| CVE-2024-31587 | MEDIUM | 6.5 | 0.2% | Apr 19, 2024 | SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device config... |
| CVE-2024-29183 | MEDIUM | 6.1 | 0.4% | Apr 19, 2024 | OpenRASP is a RASP solution that directly integrates its protection engine into the application server by instrumentatio... |
| CVE-2024-29029 | MEDIUM | 6.1 | 1.1% | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/i... |
| CVE-2024-27752 | MEDIUM | 5.4 | 0.6% | Apr 19, 2024 | Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default... |
| CVE-2024-22640 | HIGH | 7.5 | 1.3% | Apr 19, 2024 | TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page wi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now