2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23771 | CRITICAL | 9.8 | 1.1% | Jan 22, 2024 | darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remot... |
| CVE-2024-23770 | MEDIUM | 5.5 | 0.2% | Jan 22, 2024 | darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments. |
| CVE-2024-23768 | HIGH | 8.8 | 0.6% | Jan 22, 2024 | Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the file... |
| CVE-2024-23752 | CRITICAL | 9.8 | 1.0% | Jan 22, 2024 | GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the ge... |
| CVE-2024-23751 | CRITICAL | 9.8 | 0.7% | Jan 22, 2024 | LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, S... |
| CVE-2024-23750 | HIGH | 8.8 | 1.0% | Jan 22, 2024 | MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell met... |
| CVE-2024-0776 | MEDIUM | 5.4 | 0.6% | Jan 22, 2024 | A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms 2.0. Affected by this issue i... |
| CVE-2024-0774 | MEDIUM | 5.5 | 0.3% | Jan 22, 2024 | A vulnerability was found in Any-Capture Any Sound Recorder 2.93. It has been declared as problematic. This vulnerabilit... |
| CVE-2024-0773 | MEDIUM | 5.4 | 0.6% | Jan 22, 2024 | A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerabi... |
| CVE-2024-0772 | MEDIUM | 5.5 | 0.4% | Jan 22, 2024 | A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some u... |
| CVE-2024-23744 | HIGH | 7.5 | 0.7% | Jan 21, 2024 | An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello ... |
| CVE-2024-0771 | MEDIUM | 5.5 | 0.3% | Jan 21, 2024 | A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vul... |
| CVE-2024-0770 | HIGH | 7.1 | 0.3% | Jan 21, 2024 | A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affe... |
| CVE-2024-23732 | HIGH | 7.5 | 0.8% | Jan 21, 2024 | The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to j... |
| CVE-2024-23731 | CRITICAL | 9.8 | 1.1% | Jan 21, 2024 | The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yam... |
| CVE-2024-23730 | CRITICAL | 9.8 | 1.2% | Jan 21, 2024 | The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary co... |
| CVE-2024-0769 | CRITICAL | 9.8 | 82.7% | Jan 21, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affe... |
| CVE-2024-23726 | HIGH | 8.8 | 0.5% | Jan 21, 2024 | Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote... |
| CVE-2024-23725 | MEDIUM | 6.1 | 0.4% | Jan 21, 2024 | Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries. |
| CVE-2024-0521 | HIGH | 7.8 | 0.5% | Jan 20, 2024 | Code Injection in paddlepaddle/paddle |
| CVE-2024-0679 | MEDIUM | 6.5 | 1.3% | Jan 20, 2024 | The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_ac... |
| CVE-2024-0623 | MEDIUM | 4.3 | 0.7% | Jan 20, 2024 | The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2024-23332 | MEDIUM | 6.8 | 0.3% | Jan 19, 2024 | The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing softw... |
| CVE-2024-23688 | MEDIUM | 5.3 | 0.5% | Jan 19, 2024 | Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be... |
| CVE-2024-23687 | CRITICAL | 9.1 | 0.6% | Jan 19, 2024 | Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthentica... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now