2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58357HIGH7.1SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics whe...
CVE-2024-58356MEDIUM6.3SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used ...
CVE-2024-42214MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method ...
CVE-2024-23578MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) ...
CVE-2024-23577MEDIUM4.3HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary...
CVE-2024-23575MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information ...
CVE-2024-23574MEDIUM5.3HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to ...
CVE-2024-23573LOW3.7HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 ...
CVE-2024-23572MEDIUM4.2HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as...
CVE-2024-23571MEDIUM4.3HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying...
CVE-2024-23570MEDIUM4.3HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta...
CVE-2024-23569MEDIUM4.3HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23568MEDIUM5.3HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th...
CVE-2024-23567MEDIUM4.3HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti...
CVE-2024-23566MEDIUM6.5HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead...
CVE-2024-23565MEDIUM5.3HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism ...
CVE-2024-23564CRITICAL9.1HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obta...
CVE-2024-34268HIGH7.1EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow ...
CVE-2024-32389LOW3.5Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attack...
CVE-2024-32387MEDIUM5.7An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv...
CVE-2024-32386HIGH7.3Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at...
CVE-2024-32385MEDIUM4.3An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv...
CVE-2024-58360MEDIUM6.9stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verifica...
CVE-2024-7708HIGH7.5For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is parti...
CVE-2024-56141MEDIUM5Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b0...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now