2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31993MEDIUM4.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an imag...
CVE-2024-31992MEDIUM6.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c...
CVE-2024-31991LOW3.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c...
CVE-2024-31584MEDIUM5.5Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader....
CVE-2024-30974HIGH7.3SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId paramete...
CVE-2024-22905HIGH7Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted s...
CVE-2024-1681MEDIUM5.3corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake lo...
CVE-2024-32652HIGH7.5The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs...
CVE-2024-31450MEDIUM6.5Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast app...
CVE-2024-3979MEDIUM4.4A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this is...
CVE-2024-31547CRITICAL9.1Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_ite...
CVE-2024-31546CRITICAL9.8Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_d...
CVE-2024-31552HIGH7.1CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitr...
CVE-2024-2440MEDIUM5.9A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository ...
CVE-2024-29991MEDIUM5Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2024-32650HIGH7.5Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop...
CVE-2024-32409HIGH7.1An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
CVE-2024-32206MEDIUM4.6A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows at...
CVE-2024-31846HIGH7.5An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access ...
CVE-2024-31841HIGH7.5An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthent...
CVE-2024-31587MEDIUM6.5SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device config...
CVE-2024-29183MEDIUM6.1OpenRASP is a RASP solution that directly integrates its protection engine into the application server by instrumentatio...
CVE-2024-29029MEDIUM6.1memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/i...
CVE-2024-27752MEDIUM5.4Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default...
CVE-2024-22640HIGH7.5TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page wi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now