2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56975CRITICAL9.8InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerabilit...
CVE-2024-38988CRITICAL9.8alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/inde...
CVE-2024-38985CRITICAL9.8janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() met...
CVE-2024-24292CRITICAL9.8A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function...
CVE-2024-54362HIGH8.1Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This is...
CVE-2024-54291HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass plugin...
CVE-2024-51624HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-...
CVE-2024-48615HIGH7.5Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pa...
CVE-2024-39311MEDIUM5.4Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions...
CVE-2024-7407HIGH8.2Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords ...
CVE-2024-11504HIGH8.6Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, w...
CVE-2024-12619MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17....
CVE-2024-10307MEDIUM5.5An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17...
CVE-2024-49601CRITICAL9.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-13939HIGH7.5String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the...
CVE-2024-49565HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-49564HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-49563HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-55070LOW3.1A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allo...
CVE-2024-55073HIGH7.6A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ...
CVE-2024-55072MEDIUM5.4A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ...
CVE-2024-12905HIGH7.5An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted ...
CVE-2024-58091MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/fbdev-dma: Add shadow buffering for deferred I/...
CVE-2024-58090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched/core: Prevent rescheduling when interrupts ar...
CVE-2024-56469MEDIUM6.3IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now