2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3872 | MEDIUM | 6.5 | 0.5% | Apr 16, 2024 | Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain d... |
| CVE-2024-32634 | MEDIUM | 6.1 | 0.3% | Apr 16, 2024 | In huge memory get unmapped area check, code can never be reached because of a logical contradiction. |
| CVE-2024-32633 | MEDIUM | 4 | 0.2% | Apr 16, 2024 | An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way. |
| CVE-2024-32632 | MEDIUM | 6.6 | 0.2% | Apr 16, 2024 | A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access |
| CVE-2024-32625 | MEDIUM | 5.8 | 0.4% | Apr 16, 2024 | In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computa... |
| CVE-2024-32557 | MEDIUM | 5.4 | 0.3% | Apr 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons E... |
| CVE-2024-31784 | MEDIUM | 6.1 | 0.3% | Apr 16, 2024 | An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary co... |
| CVE-2024-31783 | MEDIUM | 6.1 | 0.4% | Apr 16, 2024 | Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive infor... |
| CVE-2024-31634 | MEDIUM | 6.1 | 0.6% | Apr 16, 2024 | Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbit... |
| CVE-2024-3575 | MEDIUM | 6.1 | 0.4% | Apr 16, 2024 | Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb |
| CVE-2024-30567 | MEDIUM | 6.3 | 0.6% | Apr 16, 2024 | An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via ... |
| CVE-2024-2260 | MEDIUM | 4.2 | 0.4% | Apr 16, 2024 | A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication... |
| CVE-2024-1666 | MEDIUM | 5.3 | 0.5% | Apr 16, 2024 | In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerabili... |
| CVE-2024-1183 | MEDIUM | 6.5 | 1.8% | Apr 16, 2024 | An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to sc... |
| CVE-2024-27794 | MEDIUM | 6.1 | 0.3% | Apr 15, 2024 | Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to a... |
| CVE-2024-31651 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-31652 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-31649 | MEDIUM | 5.4 | 0.4% | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web... |
| CVE-2024-31648 | MEDIUM | 6.1 | 0.5% | Apr 15, 2024 | Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts... |
| CVE-2024-23561 | MEDIUM | 4.3 | 0.4% | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfus... |
| CVE-2024-23558 | MEDIUM | 6.3 | 0.3% | Apr 15, 2024 | HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to imper... |
| CVE-2024-3804 | MEDIUM | 6.3 | 0.5% | Apr 15, 2024 | A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue a... |
| CVE-2024-32036 | MEDIUM | 6.5 | 0.6% | Apr 15, 2024 | ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability... |
| CVE-2024-32035 | MEDIUM | 6.5 | 0.6% | Apr 15, 2024 | ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially... |
| CVE-2024-31990 | MEDIUM | 6.3 | 0.4% | Apr 15, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project source... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now