2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38316MEDIUM6.5IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can sen...
CVE-2024-57699HIGH7.5A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, conta...
CVE-2024-57598MEDIUM6.5A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() ...
CVE-2024-57520CRITICAL9.8Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_cre...
CVE-2024-57086HIGH7.5A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a De...
CVE-2024-57085HIGH7.5A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Se...
CVE-2024-57084HIGH7.5A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to cause a Denial of Service (...
CVE-2024-57082MEDIUM6.5A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of...
CVE-2024-57081HIGH7.5A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of S...
CVE-2024-57080HIGH7.5A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (Do...
CVE-2024-57079HIGH7.5A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Servic...
CVE-2024-57078HIGH7.5A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) ...
CVE-2024-57077CRITICAL9.1The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend...
CVE-2024-57076HIGH7.5A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS...
CVE-2024-57075HIGH7.5A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (Do...
CVE-2024-57074HIGH7.5A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) ...
CVE-2024-57072HIGH7.5A prototype pollution in the lib.requireFromString function of module-from-string v3.3.1 allows attackers to cause a Den...
CVE-2024-57071HIGH7.5A prototype pollution in the lib.combine function of php-parser v3.2.1 allows attackers to cause a Denial of Service (Do...
CVE-2024-57069HIGH7.5A prototype pollution in the lib function of expand-object v0.4.2 allows attackers to cause a Denial of Service (DoS) vi...
CVE-2024-57068HIGH7.5A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Den...
CVE-2024-57067HIGH7.5A prototype pollution in the lib.parse function of dot-qs v0.2.0 allows attackers to cause a Denial of Service (DoS) via...
CVE-2024-57066HIGH7.5A prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service...
CVE-2024-57065HIGH7.5A prototype pollution in the lib.createPath function of utile v0.3.0 allows attackers to cause a Denial of Service (DoS)...
CVE-2024-57064HIGH7.5A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a De...
CVE-2024-57063HIGH7.5A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (Do...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now