2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27284HIGH7.5cassandra-rs is a Cassandra (CQL) driver for Rust. Code that attempts to use an item (e.g., a row) returned by an iterat...
CVE-2024-27092MEDIUM5.4Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad...
CVE-2024-27083MEDIUM6.1Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerabil...
CVE-2024-26473MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious J...
CVE-2024-26472MEDIUM6.1KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may ...
CVE-2024-26471MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaS...
CVE-2024-26470HIGH8.1A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v...
CVE-2024-26462MEDIUM5.5Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
CVE-2024-26461HIGH7.5Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CVE-2024-26458MEDIUM5.3Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
CVE-2024-26132LOW3.3Element Android is an Android Matrix Client. A third-party malicious application installed on the same phone can force E...
CVE-2024-26131HIGH7.8Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redire...
CVE-2024-25932HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows C...
CVE-2024-25931HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1....
CVE-2024-25930HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Cu...
CVE-2024-25833CRITICAL9.8F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious ac...
CVE-2024-25832HIGH8.8F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to ...
CVE-2024-25831MEDIUM5.4F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input ...
CVE-2024-25830CRITICAL9.8F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una...
CVE-2024-25713HIGH8.6yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function l...
CVE-2024-25712MEDIUM6.1http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandle...
CVE-2024-25262HIGH8.1texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulne...
CVE-2024-25128CRITICAL9.1Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TY...
CVE-2024-25065CRITICAL9.1Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.1...
CVE-2024-25006HIGH8.1XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to adm...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now