2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1351 | CRITICAL | 9.8 | 0.5% | Mar 7, 2024 | Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which ma... |
| CVE-2024-0818 | CRITICAL | 9.1 | 1.0% | Mar 7, 2024 | Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6 |
| CVE-2024-0917 | CRITICAL | 9.8 | 1.6% | Mar 7, 2024 | remote code execution in paddlepaddle/paddle 2.6.0 |
| CVE-2024-28222 | CRITICAL | 9.8 | 1.0% | Mar 7, 2024 | In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file... |
| CVE-2024-28213 | CRITICAL | 9.8 | 1.2% | Mar 7, 2024 | nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote atta... |
| CVE-2024-28212 | CRITICAL | 9.8 | 1.0% | Mar 7, 2024 | nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via uns... |
| CVE-2024-28211 | CRITICAL | 9.8 | 0.8% | Mar 7, 2024 | nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing ar... |
| CVE-2024-22857 | CRITICAL | 9.8 | 1.7% | Mar 7, 2024 | Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but... |
| CVE-2024-27308 | CRITICAL | 9.1 | 0.9% | Mar 6, 2024 | Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid... |
| CVE-2024-27307 | CRITICAL | 9.8 | 1.4% | Mar 6, 2024 | JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a m... |
| CVE-2024-27304 | CRITICAL | 9.8 | 1.1% | Mar 6, 2024 | pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind m... |
| CVE-2024-27302 | CRITICAL | 9.1 | 0.8% | Mar 6, 2024 | go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - whic... |
| CVE-2024-24767 | CRITICAL | 9.8 | 1.0% | Mar 6, 2024 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version ... |
| CVE-2024-24765 | CRITICAL | 9.8 | 1.0% | Mar 6, 2024 | CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL... |
| CVE-2024-26580 | CRITICAL | 9.1 | 1.2% | Mar 6, 2024 | Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.... |
| CVE-2024-27764 | CRITICAL | 9.8 | 1.0% | Mar 5, 2024 | An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component. |
| CVE-2024-24276 | CRITICAL | 9.6 | 0.9% | Mar 5, 2024 | Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote atta... |
| CVE-2024-24275 | CRITICAL | 9.6 | 0.9% | Mar 5, 2024 | Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker t... |
| CVE-2024-25614 | CRITICAL | 9.1 | 0.5% | Mar 5, 2024 | There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerabil... |
| CVE-2024-2056 | CRITICAL | 9.8 | 16.7% | Mar 5, 2024 | Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy servi... |
| CVE-2024-2055 | CRITICAL | 9.8 | 0.9% | Mar 5, 2024 | The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the... |
| CVE-2024-27565 | CRITICAL | 9.8 | 0.7% | Mar 5, 2024 | A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force t... |
| CVE-2024-26339 | CRITICAL | 9.1 | 0.8% | Mar 5, 2024 | swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a. |
| CVE-2024-2048 | CRITICAL | 9.8 | 0.4% | Mar 4, 2024 | Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con... |
| CVE-2024-27198 | CRITICAL | 9.8 | 99.9% | Mar 4, 2024 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now