2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11944HIGH8.8iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability al...
CVE-2024-56801CRITICAL9.8Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version ...
CVE-2024-56800HIGH7.4Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions pr...
CVE-2024-56799CRITICAL10Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistak...
CVE-2024-46542MEDIUM6.5Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks.
CVE-2024-56734MEDIUM6.1Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verif...
CVE-2024-56733MEDIUM5.7Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has bee...
CVE-2024-56517MEDIUM5.3LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 con...
CVE-2024-56516MEDIUM6.9free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API f...
CVE-2024-52294MEDIUM4.3Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR...
CVE-2024-12836HIGH7.8Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-12835HIGH7.8Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2024-12834HIGH7.8Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-12828HIGH8.8Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ...
CVE-2024-12754MEDIUM5.5AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensi...
CVE-2024-50703HIGH8.1TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
CVE-2024-50702MEDIUM5.3TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an adminis...
CVE-2024-50701MEDIUM4.3TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a...
CVE-2024-54181HIGH7.2IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to exe...
CVE-2024-10044CRITICAL9.3A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro...
CVE-2024-12993MEDIUM4.8Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An atta...
CVE-2024-47926CRITICAL9.8Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-47925HIGH7.5Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-47924HIGH7.5Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-47923MEDIUM5.3Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now