2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1456 | HIGH | 7.1 | 0.2% | Apr 16, 2024 | An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http... |
| CVE-2024-1183 | MEDIUM | 6.5 | 1.8% | Apr 16, 2024 | An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to sc... |
| CVE-2024-1135 | HIGH | 7.5 | 3.0% | Apr 16, 2024 | Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. ... |
| CVE-2024-0549 | HIGH | 8.1 | 0.8% | Apr 16, 2024 | mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a def... |
| CVE-2024-0404 | CRITICAL | 9.1 | 0.8% | Apr 16, 2024 | A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository,... |
| CVE-2024-27794 | MEDIUM | 6.1 | 0.3% | Apr 15, 2024 | Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to a... |
| CVE-2024-3493 | HIGH | 7.5 | 0.6% | Apr 15, 2024 | A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send lar... |
| CVE-2024-31651 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-30656 | HIGH | 7.5 | 0.4% | Apr 15, 2024 | An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of S... |
| CVE-2024-2424 | HIGH | 7.5 | 2.6% | Apr 15, 2024 | An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to r... |
| CVE-2024-31652 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-31650 | CRITICAL | 9.6 | 0.8% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-31649 | MEDIUM | 5.4 | 0.4% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-31648 | MEDIUM | 6.1 | 0.5% | Apr 15, 2024 | Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts... |
| CVE-2024-23561 | MEDIUM | 4.3 | 0.4% | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfus... |
| CVE-2024-23558 | MEDIUM | 6.3 | 0.3% | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to imper... |
| CVE-2024-3804 | MEDIUM | 6.3 | 0.5% | Apr 15, 2024 | A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue a... |
| CVE-2024-32036 | MEDIUM | 6.5 | 0.6% | Apr 15, 2024 | ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability... |
| CVE-2024-32035 | MEDIUM | 6.5 | 0.6% | Apr 15, 2024 | ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially... |
| CVE-2024-31990 | MEDIUM | 6.3 | 0.4% | Apr 15, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project source... |
| CVE-2024-31497 | MEDIUM | 5.9 | 5.8% | Apr 15, 2024 | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 ... |
| CVE-2024-30840 | MEDIUM | 6.5 | 0.3% | Apr 15, 2024 | A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN p... |
| CVE-2024-23560 | MEDIUM | 4.9 | 0.3% | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom securi... |
| CVE-2024-3803 | MEDIUM | 6.3 | 0.5% | Apr 15, 2024 | A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects un... |
| CVE-2024-28558 | HIGH | 8.8 | 1.2% | Apr 15, 2024 | SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now