2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57077CRITICAL9.1The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend...
CVE-2024-57076HIGH7.5A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS...
CVE-2024-57075HIGH7.5A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (Do...
CVE-2024-57074HIGH7.5A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) ...
CVE-2024-57072HIGH7.5A prototype pollution in the lib.requireFromString function of module-from-string v3.3.1 allows attackers to cause a Den...
CVE-2024-57071HIGH7.5A prototype pollution in the lib.combine function of php-parser v3.2.1 allows attackers to cause a Denial of Service (Do...
CVE-2024-57069HIGH7.5A prototype pollution in the lib function of expand-object v0.4.2 allows attackers to cause a Denial of Service (DoS) vi...
CVE-2024-57068HIGH7.5A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Den...
CVE-2024-57067HIGH7.5A prototype pollution in the lib.parse function of dot-qs v0.2.0 allows attackers to cause a Denial of Service (DoS) via...
CVE-2024-57066HIGH7.5A prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service...
CVE-2024-57065HIGH7.5A prototype pollution in the lib.createPath function of utile v0.3.0 allows attackers to cause a Denial of Service (DoS)...
CVE-2024-57064HIGH7.5A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a De...
CVE-2024-57063HIGH7.5A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (Do...
CVE-2024-54853MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and e...
CVE-2024-48394HIGH7.8A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which...
CVE-2024-7596MEDIUM6.5Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing ...
CVE-2024-7595MEDIUM6.5GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof ...
CVE-2024-56135MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-56134MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-56133MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-56132MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-56131MEDIUM6.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi...
CVE-2024-42207MEDIUM6HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from thei...
CVE-2024-39564HIGH8.7This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability i...
CVE-2024-9097MEDIUM4.3ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacke...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now