2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2053HIGH7.5The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users...
CVE-2024-2016HIGH8.8A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file a...
CVE-2024-2015HIGH8.8A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getinde...
CVE-2024-2014CRITICAL9.8A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown cod...
CVE-2024-2007HIGH8.8A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerability is a...
CVE-2024-28286HIGH7.5In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c f...
CVE-2024-28123CRITICAL9.8Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the W...
CVE-2024-28102MEDIUM6.8JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can ...
CVE-2024-28101HIGH7.5The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions ...
CVE-2024-27936MEDIUM6.5Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to ...
CVE-2024-27935HIGH8.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vul...
CVE-2024-27934HIGH8.8Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to version 1.40.3, use o...
CVE-2024-27933HIGH8.8Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ip...
CVE-2024-27932MEDIUM4.6Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno i...
CVE-2024-27927MEDIUM6.5RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to us...
CVE-2024-27926MEDIUM6.1RSSHub is an open source RSS feed generator. Starting in version 1.0.0-master.cbbd829 and prior to version 1.0.0-master....
CVE-2024-27923HIGH8.8Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter`...
CVE-2024-27922CRITICAL9.8TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure han...
CVE-2024-27918HIGH8.2Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, a...
CVE-2024-27916MEDIUM4.3Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRe...
CVE-2024-27626MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists withi...
CVE-2024-27292HIGH7.5Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain ...
CVE-2024-27291MEDIUM6.1Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a...
CVE-2024-27290MEDIUM6.1Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, a user could type HTML int...
CVE-2024-27105MEDIUM6.5Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now