2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2053 | HIGH | 7.5 | 44.6% | Mar 21, 2024 | The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users... |
| CVE-2024-2016 | HIGH | 8.8 | 1.0% | Mar 21, 2024 | A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file a... |
| CVE-2024-2015 | HIGH | 8.8 | 0.8% | Mar 21, 2024 | A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getinde... |
| CVE-2024-2014 | CRITICAL | 9.8 | 1.1% | Mar 21, 2024 | A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown cod... |
| CVE-2024-2007 | HIGH | 8.8 | 0.3% | Mar 21, 2024 | A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerability is a... |
| CVE-2024-28286 | HIGH | 7.5 | 0.7% | Mar 21, 2024 | In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c f... |
| CVE-2024-28123 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the W... |
| CVE-2024-28102 | MEDIUM | 6.8 | 1.0% | Mar 21, 2024 | JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can ... |
| CVE-2024-28101 | HIGH | 7.5 | 0.8% | Mar 21, 2024 | The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions ... |
| CVE-2024-27936 | MEDIUM | 6.5 | 0.9% | Mar 21, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to ... |
| CVE-2024-27935 | HIGH | 8.3 | 0.7% | Mar 21, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vul... |
| CVE-2024-27934 | HIGH | 8.8 | 0.4% | Mar 21, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to version 1.40.3, use o... |
| CVE-2024-27933 | HIGH | 8.8 | 2.3% | Mar 21, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ip... |
| CVE-2024-27932 | MEDIUM | 4.6 | 0.6% | Mar 21, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno i... |
| CVE-2024-27927 | MEDIUM | 6.5 | 1.0% | Mar 21, 2024 | RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to us... |
| CVE-2024-27926 | MEDIUM | 6.1 | 0.5% | Mar 21, 2024 | RSSHub is an open source RSS feed generator. Starting in version 1.0.0-master.cbbd829 and prior to version 1.0.0-master.... |
| CVE-2024-27923 | HIGH | 8.8 | 1.4% | Mar 21, 2024 | Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter`... |
| CVE-2024-27922 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure han... |
| CVE-2024-27918 | HIGH | 8.2 | 1.0% | Mar 21, 2024 | Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, a... |
| CVE-2024-27916 | MEDIUM | 4.3 | 0.7% | Mar 21, 2024 | Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRe... |
| CVE-2024-27626 | MEDIUM | 6.1 | 0.4% | Mar 21, 2024 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists withi... |
| CVE-2024-27292 | HIGH | 7.5 | 69.5% | Mar 21, 2024 | Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain ... |
| CVE-2024-27291 | MEDIUM | 6.1 | 0.4% | Mar 21, 2024 | Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a... |
| CVE-2024-27290 | MEDIUM | 6.1 | 0.4% | Mar 21, 2024 | Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, a user could type HTML int... |
| CVE-2024-27105 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now