2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23771CRITICAL9.8darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remot...
CVE-2024-23770MEDIUM5.5darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
CVE-2024-23768HIGH8.8Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the file...
CVE-2024-23752CRITICAL9.8GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the ge...
CVE-2024-23751CRITICAL9.8LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, S...
CVE-2024-23750HIGH8.8MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell met...
CVE-2024-0776MEDIUM5.4A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms 2.0. Affected by this issue i...
CVE-2024-0774MEDIUM5.5A vulnerability was found in Any-Capture Any Sound Recorder 2.93. It has been declared as problematic. This vulnerabilit...
CVE-2024-0773MEDIUM5.4A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerabi...
CVE-2024-0772MEDIUM5.5A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some u...
CVE-2024-23744HIGH7.5An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello ...
CVE-2024-0771MEDIUM5.5A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vul...
CVE-2024-0770HIGH7.1A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affe...
CVE-2024-23732HIGH7.5The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to j...
CVE-2024-23731CRITICAL9.8The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yam...
CVE-2024-23730CRITICAL9.8The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary co...
CVE-2024-0769CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affe...
CVE-2024-23726HIGH8.8Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote...
CVE-2024-23725MEDIUM6.1Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.
CVE-2024-0521HIGH7.8Code Injection in paddlepaddle/paddle
CVE-2024-0679MEDIUM6.5The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_ac...
CVE-2024-0623MEDIUM4.3The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-23332MEDIUM6.8The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing softw...
CVE-2024-23688MEDIUM5.3Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be...
CVE-2024-23687CRITICAL9.1Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthentica...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now