2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28111MEDIUM6.5Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canaryt...
CVE-2024-28110HIGH7.5Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15...
CVE-2024-27917HIGH7.5Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session C...
CVE-2024-27915HIGH8.1Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to page...
CVE-2024-27308CRITICAL9.1Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid...
CVE-2024-27307CRITICAL9.8JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a m...
CVE-2024-2176HIGH8.8Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap c...
CVE-2024-2174HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exp...
CVE-2024-2173HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of b...
CVE-2024-27304CRITICAL9.8pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind m...
CVE-2024-27303HIGH7.3electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Wind...
CVE-2024-27302CRITICAL9.1go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - whic...
CVE-2024-27289HIGH8.1pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the followin...
CVE-2024-27288LOW3.11Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can...
CVE-2024-27287HIGH8.7ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior t...
CVE-2024-25111HIGH7.5Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of ...
CVE-2024-24766HIGH7.5CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version ...
CVE-2024-24767CRITICAL9.8CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version ...
CVE-2024-24765CRITICAL9.8CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL...
CVE-2024-24761HIGH7.5Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to ...
CVE-2024-2216HIGH8.8A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers wit...
CVE-2024-2215MEDIUM6.1A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers ...
CVE-2024-28174MEDIUM5.8In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized i...
CVE-2024-28173MEDIUM4.3In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
CVE-2024-28162MEDIUM4.2In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable S...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now