2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-1351CRITICAL9.8Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which ma...
CVE-2024-0818CRITICAL9.1Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6
CVE-2024-0917CRITICAL9.8remote code execution in paddlepaddle/paddle 2.6.0
CVE-2024-28222CRITICAL9.8In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file...
CVE-2024-28213CRITICAL9.8nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote atta...
CVE-2024-28212CRITICAL9.8nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via uns...
CVE-2024-28211CRITICAL9.8nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing ar...
CVE-2024-22857CRITICAL9.8Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but...
CVE-2024-27308CRITICAL9.1Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid...
CVE-2024-27307CRITICAL9.8JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a m...
CVE-2024-27304CRITICAL9.8pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind m...
CVE-2024-27302CRITICAL9.1go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - whic...
CVE-2024-24767CRITICAL9.8CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version ...
CVE-2024-24765CRITICAL9.8CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL...
CVE-2024-26580CRITICAL9.1Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1....
CVE-2024-27764CRITICAL9.8An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
CVE-2024-24276CRITICAL9.6Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote atta...
CVE-2024-24275CRITICAL9.6Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker t...
CVE-2024-25614CRITICAL9.1There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerabil...
CVE-2024-2056CRITICAL9.8Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy servi...
CVE-2024-2055CRITICAL9.8The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the...
CVE-2024-27565CRITICAL9.8A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force t...
CVE-2024-26339CRITICAL9.1swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.
CVE-2024-2048CRITICAL9.8Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con...
CVE-2024-27198CRITICAL9.8In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now