2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58369HIGH7.1SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names...
CVE-2024-58368HIGH8.7SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing s...
CVE-2024-58367HIGH7.1SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations,...
CVE-2024-58366CRITICAL9SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script...
CVE-2024-58365HIGH7.1SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls ...
CVE-2024-58364MEDIUM6.5SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer...
CVE-2024-58363MEDIUM6.3SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clau...
CVE-2024-58362HIGH8.8SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operati...
CVE-2024-58361HIGH7.1SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code ...
CVE-2024-58359HIGH7.1SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY r...
CVE-2024-58358MEDIUM6.9SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owne...
CVE-2024-58357HIGH7.1SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics whe...
CVE-2024-58356LOW2.3SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used ...
CVE-2024-42214MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method ...
CVE-2024-23578MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) ...
CVE-2024-23577MEDIUM4.3HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary...
CVE-2024-23575MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information ...
CVE-2024-23574MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to ...
CVE-2024-23573LOW3.7HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 ...
CVE-2024-23572MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as...
CVE-2024-23571MEDIUM4.3HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying...
CVE-2024-23570MEDIUM4.3HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta...
CVE-2024-23569MEDIUM4.3HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23568MEDIUM5.3HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th...
CVE-2024-23567MEDIUM4.3HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now