2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28447MEDIUM6.5Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_ipaddr pa...
CVE-2024-28446MEDIUM5.7Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_netmask p...
CVE-2024-26369HIGH7.5An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal a...
CVE-2024-22025MEDIUM6.5A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustio...
CVE-2024-22017HIGH7.3setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows th...
CVE-2024-21504MEDIUM6.1Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when ...
CVE-2024-21503MEDIUM5.3Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines...
CVE-2024-2622CRITICAL9.8A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318. It has been clas...
CVE-2024-2621CRITICAL9.8A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as...
CVE-2024-2620CRITICAL9.8A vulnerability has been found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classifi...
CVE-2024-28865HIGH7.5django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciou...
CVE-2024-28864LOW2.6SecureProps is a PHP library designed to simplify the encryption and decryption of property data in objects. A vulnerabi...
CVE-2024-28855MEDIUM6.1ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use...
CVE-2024-28250MEDIUM6.1Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 an...
CVE-2024-28249MEDIUM6.1Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1....
CVE-2024-28248HIGH7.2Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 an...
CVE-2024-28237MEDIUM4.8OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.9.3...
CVE-2024-24578CRITICAL9.8RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior ...
CVE-2024-2604CRITICAL9.8A vulnerability was found in SourceCodester File Manager App 1.0. It has been declared as critical. This vulnerability a...
CVE-2024-23333MEDIUM6.6LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration al...
CVE-2024-22412MEDIUM4.9ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering p...
CVE-2024-25657MEDIUM5.4An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07...
CVE-2024-25656MEDIUM5.9Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated ...
CVE-2024-25655MEDIUM6.5Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23....
CVE-2024-25654MEDIUM5.5Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with l...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now