2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-27993HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista...
CVE-2024-29880HIGH7.8In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running...
CVE-2024-1394HIGH7.5A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion ...
CVE-2024-29131HIGH7.3Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from ...
CVE-2024-2754HIGH8.8A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unk...
CVE-2024-2162HIGH8.8An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on...
CVE-2024-29862HIGH7.5The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wr...
CVE-2024-1538HIGH8.8The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-2053HIGH7.5The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users...
CVE-2024-2016HIGH8.8A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file a...
CVE-2024-2015HIGH8.8A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getinde...
CVE-2024-2007HIGH8.8A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerability is a...
CVE-2024-28286HIGH7.5In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c f...
CVE-2024-28101HIGH7.5The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions ...
CVE-2024-27935HIGH8.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vul...
CVE-2024-27934HIGH8.8Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to version 1.40.3, use o...
CVE-2024-27933HIGH8.8Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ip...
CVE-2024-27923HIGH8.8Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter`...
CVE-2024-27918HIGH8.2Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, a...
CVE-2024-27292HIGH7.5Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain ...
CVE-2024-27094HIGH7.4OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes...
CVE-2024-24813HIGH7.5Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular ...
CVE-2024-24520HIGH7.8An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languag...
CVE-2024-28916HIGH8.8Xbox Gaming Services Elevation of Privilege Vulnerability
CVE-2024-2469HIGH7.2An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now