2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11145CRITICAL9.8Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker t...
CVE-2024-10240MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting...
CVE-2024-8237HIGH7.5A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5...
CVE-2024-8177HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 pr...
CVE-2024-8114HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17....
CVE-2024-53844MEDIUM6.3E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerab...
CVE-2024-53620MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execut...
CVE-2024-53619MEDIUM6.3An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute ...
CVE-2024-53267MEDIUM5.5sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver...
CVE-2024-52008HIGH8.8Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password...
CVE-2024-32965HIGH8.6Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnera...
CVE-2024-11828HIGH7.5A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17....
CVE-2024-11669HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 b...
CVE-2024-11668MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17...
CVE-2024-51058MEDIUM6.2Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read a...
CVE-2024-10878MEDIUM6.1The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to...
CVE-2024-53555HIGH8.8A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV fil...
CVE-2024-53365MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 i...
CVE-2024-11407HIGH7.5There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled ...
CVE-2024-11177Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-52337MEDIUM5.5A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows ...
CVE-2024-52336HIGH7.8A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be call...
CVE-2024-36463HIGH8.8The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal...
CVE-2024-22117LOW2.2When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the s...
CVE-2024-9929MEDIUM4.3A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login informati...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now