2024 CVE Vulnerabilities

39,233 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3872MEDIUM6.5Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain d...
CVE-2024-32634MEDIUM6.1In huge memory get unmapped area check, code can never be reached because of a logical contradiction.
CVE-2024-32633MEDIUM4An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way.
CVE-2024-32632MEDIUM6.6A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access
CVE-2024-32625MEDIUM5.8In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computa...
CVE-2024-32557MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons E...
CVE-2024-31784MEDIUM6.1An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary co...
CVE-2024-31783MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive infor...
CVE-2024-31634MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbit...
CVE-2024-3575MEDIUM6.1Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb
CVE-2024-30567MEDIUM6.3An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via ...
CVE-2024-2260MEDIUM4.2A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication...
CVE-2024-1666MEDIUM5.3In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerabili...
CVE-2024-1183MEDIUM6.5An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to sc...
CVE-2024-27794MEDIUM6.1Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to a...
CVE-2024-31651MEDIUM6.1A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-31652MEDIUM6.1A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-31649MEDIUM5.4A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web...
CVE-2024-31648MEDIUM6.1Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts...
CVE-2024-23561MEDIUM4.3HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfus...
CVE-2024-23558MEDIUM6.3HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to imper...
CVE-2024-3804MEDIUM6.3A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue a...
CVE-2024-32036MEDIUM6.5ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability...
CVE-2024-32035MEDIUM6.5ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially...
CVE-2024-31990MEDIUM6.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project source...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now