2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57077 | CRITICAL | 9.1 | 0.5% | Feb 5, 2025 | The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend... |
| CVE-2024-57076 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS... |
| CVE-2024-57075 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (Do... |
| CVE-2024-57074 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) ... |
| CVE-2024-57072 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib.requireFromString function of module-from-string v3.3.1 allows attackers to cause a Den... |
| CVE-2024-57071 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.combine function of php-parser v3.2.1 allows attackers to cause a Denial of Service (Do... |
| CVE-2024-57069 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib function of expand-object v0.4.2 allows attackers to cause a Denial of Service (DoS) vi... |
| CVE-2024-57068 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Den... |
| CVE-2024-57067 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.parse function of dot-qs v0.2.0 allows attackers to cause a Denial of Service (DoS) via... |
| CVE-2024-57066 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service... |
| CVE-2024-57065 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib.createPath function of utile v0.3.0 allows attackers to cause a Denial of Service (DoS)... |
| CVE-2024-57064 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a De... |
| CVE-2024-57063 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (Do... |
| CVE-2024-54853 | MEDIUM | 5.4 | 0.2% | Feb 5, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and e... |
| CVE-2024-48394 | HIGH | 7.8 | 0.1% | Feb 5, 2025 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which... |
| CVE-2024-7596 | MEDIUM | 6.5 | 0.8% | Feb 5, 2025 | Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing ... |
| CVE-2024-7595 | MEDIUM | 6.5 | 1.5% | Feb 5, 2025 | GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof ... |
| CVE-2024-56135 | MEDIUM | 6.8 | 0.6% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-56134 | MEDIUM | 6.8 | 0.6% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-56133 | MEDIUM | 6.8 | 0.6% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-56132 | MEDIUM | 6.8 | 6.1% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-56131 | MEDIUM | 6.8 | 0.6% | Feb 5, 2025 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi... |
| CVE-2024-42207 | MEDIUM | 6 | 0.3% | Feb 5, 2025 | HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from thei... |
| CVE-2024-39564 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability i... |
| CVE-2024-9097 | MEDIUM | 4.3 | 0.6% | Feb 5, 2025 | ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacke... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now