2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1456HIGH7.1An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http...
CVE-2024-1183MEDIUM6.5An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to sc...
CVE-2024-1135HIGH7.5Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. ...
CVE-2024-0549HIGH8.1mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a def...
CVE-2024-0404CRITICAL9.1A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository,...
CVE-2024-27794MEDIUM6.1Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to a...
CVE-2024-3493HIGH7.5 A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send lar...
CVE-2024-31651MEDIUM6.1A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-30656HIGH7.5An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of S...
CVE-2024-2424HIGH7.5 An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to r...
CVE-2024-31652MEDIUM6.1A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-31650CRITICAL9.6A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-31649MEDIUM5.4A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-31648MEDIUM6.1Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts...
CVE-2024-23561MEDIUM4.3HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfus...
CVE-2024-23558MEDIUM6.3HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to imper...
CVE-2024-3804MEDIUM6.3A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue a...
CVE-2024-32036MEDIUM6.5ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability...
CVE-2024-32035MEDIUM6.5ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially...
CVE-2024-31990MEDIUM6.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project source...
CVE-2024-31497MEDIUM5.9In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 ...
CVE-2024-30840MEDIUM6.5A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN p...
CVE-2024-23560MEDIUM4.9HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom securi...
CVE-2024-3803MEDIUM6.3A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects un...
CVE-2024-28558HIGH8.8SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now