2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0267CRITICAL9.8A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vul...
CVE-2024-0266MEDIUM5.4A vulnerability classified as problematic has been found in Project Worlds Online Lawyer Management System 1.0. Affected...
CVE-2024-0265HIGH8.8A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects...
CVE-2024-0264CRITICAL9.8A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerabil...
CVE-2024-0263HIGH7.5A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown ...
CVE-2024-0262MEDIUM4.8A vulnerability was found in Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown...
CVE-2024-0261HIGH7.5A vulnerability has been found in Sentex FTPDMIN 0.96 and classified as problematic. Affected by this vulnerability is a...
CVE-2024-0260HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected ...
CVE-2024-21642HIGH7.5D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerab...
CVE-2024-21641MEDIUM4.7Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redire...
CVE-2024-0247CRITICAL9.8A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affect...
CVE-2024-0246MEDIUM6.1A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of t...
CVE-2024-22088CRITICAL9.8Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, becaus...
CVE-2024-22087CRITICAL9.8route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, lead...
CVE-2024-22086CRITICAL9.8handle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to ...
CVE-2024-22075MEDIUM6.1Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.
CVE-2024-22051CRITICAL9.8CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in...
CVE-2024-22050HIGH7.5Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read ...
CVE-2024-22049MEDIUM5.3httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated a...
CVE-2024-22048MEDIUM6.1govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious Ja...
CVE-2024-22047LOW3.1A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to...
CVE-2024-0241HIGH7.5encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remot...
CVE-2024-21636MEDIUM6.1view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versio...
CVE-2024-21625HIGH8.8SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep l...
CVE-2024-0225HIGH8.8Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now