2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25109MEDIUM5.4ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface ...
CVE-2024-24828HIGH7.8pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written t...
CVE-2024-23327HIGH7.5Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, t...
CVE-2024-23325HIGH7.5Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that i...
CVE-2024-23324HIGH7.5Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections...
CVE-2024-23323MEDIUM5.3Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result...
CVE-2024-23322HIGH7.5Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same int...
CVE-2024-21624MEDIUM6.5nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. This security advisory pertains to...
CVE-2024-1404HIGH7.5A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unkno...
CVE-2024-1246MEDIUM4.8Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficie...
CVE-2024-1245MEDIUM4.8Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administra...
CVE-2024-1247MEDIUM4.8Concrete CMS version 9 before 9.2.5 is vulnerable to  stored XSS via the Role Name field since there is insufficient val...
CVE-2024-1402MEDIUM4.3Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom ...
CVE-2024-25454MEDIUM5.5Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.
CVE-2024-25453MEDIUM5.5Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.
CVE-2024-25452MEDIUM5.5Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.
CVE-2024-25451MEDIUM6.5Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.
CVE-2024-25450HIGH8.8imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().
CVE-2024-25448HIGH8.8An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow ...
CVE-2024-25447HIGH8.8An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer ove...
CVE-2024-25446HIGH7.8An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer over...
CVE-2024-25445HIGH7.8Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.
CVE-2024-25443HIGH7.8An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-...
CVE-2024-25442HIGH7.8An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap bu...
CVE-2024-24776MEDIUM4.3Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in chan...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now