2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31448MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-sit...
CVE-2024-51734HIGH8.7Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delet...
CVE-2024-51502MEDIUM5.1loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the ...
CVE-2024-51501CRITICAL10Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit attributes...
CVE-2024-51500HIGH7.5Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets ...
CVE-2024-48061CRITICAL9.8langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the ...
CVE-2024-48059MEDIUM6.1gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket s...
CVE-2024-48057MEDIUM6.1localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriat...
CVE-2024-48052MEDIUM6.5In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The re...
CVE-2024-48050CRITICAL9.8In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. W...
CVE-2024-10805HIGH8.8A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. T...
CVE-2024-51744LOW3.1golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` c...
CVE-2024-48463MEDIUM6.5Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within th...
CVE-2024-45185MEDIUM5.1An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108...
CVE-2024-45086MEDIUM5.5IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when process...
CVE-2024-10791CRITICAL9.8A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issu...
CVE-2024-34891MEDIUM6.8Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrator...
CVE-2024-34885MEDIUM6.8Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato...
CVE-2024-30619HIGH7.5Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the numb...
CVE-2024-30618MEDIUM6.1A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary J...
CVE-2024-30617MEDIUM5.4A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to in...
CVE-2024-30616HIGH8.8Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sens...
CVE-2024-10768MEDIUM5.4A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects...
CVE-2024-51329HIGH8.8A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user in...
CVE-2024-51328MEDIUM6.1Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote atta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now