2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-24686HIGH7.8Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially cr...
CVE-2024-24685HIGH7.8Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially cr...
CVE-2024-24684HIGH7.8Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially cr...
CVE-2024-23951HIGH8.8Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A speciall...
CVE-2024-23950HIGH8.8Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A speciall...
CVE-2024-23949HIGH8.8Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A speciall...
CVE-2024-23948HIGH8.8Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A speciall...
CVE-2024-23947HIGH8.8Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A speciall...
CVE-2024-22181HIGH7.8An out-of-bounds write vulnerability exists in the readNODE functionality of libigl v2.5.0. A specially crafted .node fi...
CVE-2024-5415HIGH7.1A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS...
CVE-2024-5414HIGH7.1A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS...
CVE-2024-3657HIGH7.5A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server,...
CVE-2024-5411HIGH8.8Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated...
CVE-2024-28886HIGH8.4OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UT...
CVE-2024-29078HIGH7.5Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may al...
CVE-2024-36428HIGH8.1OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.
CVE-2024-36426HIGH7.5In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a clea...
CVE-2024-29415HIGH8.1The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2...
CVE-2024-35182HIGH8.1Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur...
CVE-2024-35181HIGH8.1Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur...
CVE-2024-35237HIGH7.5MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants ...
CVE-2024-35231HIGH8.6rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-...
CVE-2024-35219HIGH8.3OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configurat...
CVE-2024-34477HIGH7.8configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafte...
CVE-2024-5035HIGH8.8The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now